Program analysis method, device and electronic equipment

By combining a multi-dimensional approach of static feature comparison, dynamic behavior detection, and behavior correlation analysis, the shortcomings of static analysis methods in risk analysis in complex code environments are addressed, achieving more reliable risk analysis results.

CN119646818BActive Publication Date: 2025-09-23BEIJING BAIDU NETCOM SCI & TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411668372.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-20
Publication Date
2025-09-23
Estimated Expiration
2044-11-20

AI Technical Summary

Technical Problem

When faced with complex code obfuscation and self-modifying code technologies, existing static analysis methods have a single analysis dimension and are unable to effectively capture the dynamic behavior of applications, resulting in insufficient reliability of risk analysis results.

Method used

Combining static feature comparison strategy, dynamic behavior detection strategy and behavior correlation analysis strategy, we conduct multi-dimensional analysis of the target program's code snippets and behaviors, obtain risk analysis results through static feature comparison and dynamic behavior detection, and use behavior correlation to analyze unknown behaviors.

Benefits of technology

It improves the reliability of risk analysis results, can analyze target programs from multiple dimensions, capture dynamic behaviors, and enhance the ability to detect risky behaviors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119646818B_ABST
    Figure CN119646818B_ABST
Patent Text Reader

Abstract

The present disclosure provides a program analysis method, device, and electronic device, relating to the field of computer technology, particularly to application development, mobile product security, information technology, network security testing, network security defense, financial risk control, and other application fields. A specific implementation scheme comprises: obtaining multiple features to be analyzed from a target program; performing risk analysis on the multiple features to be analyzed using a static feature comparison strategy and / or a dynamic behavior detection strategy, obtaining a first risk analysis result for the multiple features to be analyzed; performing risk analysis on unknown behaviors using a behavior correlation analysis strategy, obtaining a second risk analysis result for the unknown behaviors; wherein the unknown behaviors are determined from the multiple features to be analyzed based on the first risk analysis result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technology, and in particular to application fields such as application development, mobile product security, information technology, network security detection, network security defense, and financial risk control, and specifically to a program analysis method, device, and electronic device. Background Art

[0002] With the rapid development of information technology, the challenges facing cybersecurity are becoming increasingly severe. Specifically, the activities of the black market industry are becoming more covert and complex, and risky code and risky behaviors hidden in applications are their core means, further exacerbating the difficulty of traditional security measures. Summary of the Invention

[0003] The present disclosure provides a program analysis method, device, and electronic device.

[0004] According to a first aspect of the present disclosure, a program analysis method is provided, comprising:

[0005] Obtain multiple features to be analyzed of the target program;

[0006] Performing risk analysis on the multiple features to be analyzed using a static feature comparison strategy and / or a dynamic behavior detection strategy to obtain a first risk analysis result for the multiple features to be analyzed;

[0007] Through the behavior correlation analysis strategy, a risk analysis is performed on the unknown behavior to obtain a second risk analysis result for the unknown behavior; wherein the unknown behavior is determined from multiple features to be analyzed based on the first risk analysis result.

[0008] According to a second aspect of the present disclosure, a program analysis method is provided, comprising:

[0009] Based on the target program, multiple features to be analyzed are obtained;

[0010] Multiple features to be analyzed are sent to a service device; wherein the service device is used to perform risk analysis on the multiple features to be analyzed through a static feature comparison strategy and / or a dynamic behavior detection strategy to obtain a first risk analysis result for the multiple features to be analyzed, and is used to perform risk analysis on unknown behaviors through a behavior correlation analysis strategy to obtain a second risk analysis result for the unknown behaviors; the unknown behaviors are determined from the multiple features to be analyzed based on the first risk analysis result.

[0011] According to a third aspect of the present disclosure, there is provided a program analysis apparatus, comprising:

[0012] A first feature acquisition unit is used to acquire a plurality of features to be analyzed of the target program;

[0013] A first risk analysis unit is configured to perform risk analysis on a plurality of features to be analyzed by using a static feature comparison strategy and / or a dynamic behavior detection strategy, and obtain a first risk analysis result for the plurality of features to be analyzed;

[0014] The second risk analysis unit is used to perform risk analysis on the unknown behavior through a behavior correlation analysis strategy to obtain a second risk analysis result for the unknown behavior; wherein the unknown behavior is determined from multiple features to be analyzed based on the first risk analysis result.

[0015] According to a fourth aspect of the present disclosure, there is provided a program analysis apparatus, comprising:

[0016] A second feature acquisition unit is used to obtain a plurality of features to be analyzed based on the target program;

[0017] A feature sending unit is used to send multiple features to be analyzed to a service device; wherein the service device is used to perform risk analysis on the multiple features to be analyzed through a static feature comparison strategy and / or a dynamic behavior detection strategy to obtain a first risk analysis result for the multiple features to be analyzed, and is used to perform risk analysis on unknown behaviors through a behavior correlation analysis strategy to obtain a second risk analysis result for the unknown behaviors; the unknown behaviors are determined from the multiple features to be analyzed based on the first risk analysis result.

[0018] According to a fifth aspect of the present disclosure, there is provided an electronic device, including:

[0019] at least one processor;

[0020] a memory communicatively coupled to the at least one processor;

[0021] The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method provided by the first aspect of the present disclosure.

[0022] According to a sixth aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to enable the computer to execute the method provided according to the first aspect of the present disclosure.

[0023] According to a seventh aspect of the present disclosure, a computer program product is provided, comprising a computer program, which implements the method provided according to the first aspect of the present disclosure when executed by a processor.

[0024] The present disclosure can improve the reliability of risk analysis results related to a target program.

[0025] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present disclosure, nor are they intended to limit the scope of the present disclosure. Other features of the present disclosure will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] The accompanying drawings are used to better understand the present invention and do not constitute a limitation of the present invention.

[0027] Figure 1 A flowchart of a program analysis method applied to a first electronic device provided in an embodiment of the present disclosure;

[0028] Figure 2 A flowchart of a program analysis method applied to a second electronic device provided in an embodiment of the present disclosure;

[0029] Figure 3 A schematic diagram of the integrity flow of a program analysis method provided in an embodiment of the present disclosure;

[0030] Figure 4 An auxiliary illustration of the integrity process of a program analysis method provided by an embodiment of the present disclosure;

[0031] Figure 5 A schematic diagram of a scenario of a program analysis method provided by an embodiment of the present disclosure;

[0032] Figure 6 A schematic structural block diagram of a program analysis device applied to a first electronic device provided by an embodiment of the present disclosure;

[0033] Figure 7 A schematic structural block diagram of a program analysis device applied to a second electronic device provided in an embodiment of the present disclosure;

[0034] Figure 8 A schematic structural block diagram of an electronic device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0035] The following description of exemplary embodiments of the present disclosure is made in conjunction with the accompanying drawings, including various details of the embodiments of the present disclosure to facilitate understanding, which should be considered as merely exemplary. Therefore, it should be appreciated by those skilled in the art that various changes and modifications may be made to the embodiments described herein without departing from the scope of the present disclosure. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.

[0036] At present, the commonly used program analysis method is static analysis. Specifically, the application can be decompiled to obtain the code decompilation results, and the code decompilation results can be cut to obtain multiple code fragments to be analyzed. Each of the multiple code fragments to be analyzed is then used as a target code fragment to compare the characteristics of the target code fragment with multiple known risk code fragments to obtain the risk analysis results for the application. However, the inventors have found that when the application is processed using complex code obfuscation technology and self-modifying code technology, the static analysis method will affect its effectiveness due to its single analysis dimension. Moreover, the static analysis method cannot capture the dynamic behavior of the application, which will ultimately seriously affect the reliability of the risk analysis results.

[0037] In view of the above problems, the embodiment of the present disclosure provides a program analysis method, which can be applied to a first electronic device. The first electronic device can be a terminal device, for example, a conventional computer (desktop computer, laptop computer, etc.), a car computer, a tablet computer, a smart phone, a personal digital assistant or other similar computing devices. Figure 1 The flowchart shown in the figure illustrates a program analysis method provided by an embodiment of the present disclosure. It should be noted that although a logical order is shown in the flowchart, in some cases, the steps shown or described in the flowchart may also be performed in other orders.

[0038] Step S101: Based on the target program, a plurality of features to be analyzed are obtained.

[0039] The target program can be any application package to be analyzed, such as an Android Application Package (APK); the multiple features to be analyzed can include multiple code snippets to be analyzed and / or multiple behaviors to be analyzed based on the target program. The multiple behaviors to be analyzed can be dynamic behaviors captured during the runtime of the target program, specifically network request behaviors, file operation behaviors, process management behaviors, system call behaviors, etc., which are not described in detail in the present embodiment.

[0040] Step S102: Send multiple features to be analyzed to a service device.

[0041] The service device can be configured to perform risk analysis on multiple features to be analyzed using a static feature comparison strategy and / or a dynamic behavior detection strategy to obtain a first risk analysis result for the multiple features to be analyzed, and to perform risk analysis on unknown behaviors using a behavior correlation analysis strategy to obtain a second risk analysis result for the unknown behaviors. Here, the unknown behaviors are determined from the multiple features to be analyzed based on the first risk analysis result.

[0042] In an embodiment of the present disclosure, a static feature comparison strategy can be used to instruct an analysis of multiple code snippets to be analyzed included in multiple features to be analyzed, and obtain an overall analysis result for the multiple code snippets to be analyzed, as a first type of analysis result for the multiple features to be analyzed; a dynamic behavior detection strategy can be used to instruct an analysis of multiple behaviors to be analyzed included in multiple features to be analyzed, and obtain an overall analysis result for the multiple behaviors to be analyzed, as a second type of analysis result for the multiple features to be analyzed. After obtaining the first type of analysis result and the second type of analysis result, a first risk analysis result for the multiple features to be analyzed can be obtained based on the first type of analysis result and the second type of analysis result. In addition, in an embodiment of the present disclosure, a behavior correlation analysis strategy can be used to instruct a correlation comparison between an unknown behavior and multiple first known risk behaviors, and obtain a second risk analysis result for the unknown behavior.

[0043] By adopting the program analysis method provided by the embodiment of the present disclosure, a plurality of features to be analyzed can be obtained based on the target program, and the plurality of features to be analyzed can be sent to the service device, and the service device can be used to obtain the plurality of features to be analyzed of the target program, and perform risk analysis on the plurality of features to be analyzed through a static feature comparison strategy and / or a dynamic behavior detection strategy, and obtain a first risk analysis result for the plurality of features to be analyzed, and then perform risk analysis on the unknown behavior (the unknown behavior is determined from the plurality of features to be analyzed based on the first risk analysis result) through a behavior correlation analysis strategy, and obtain a second risk analysis result for the unknown behavior. That is to say, in the embodiment of the present disclosure, the static feature comparison strategy and / or the dynamic behavior detection strategy, as well as the correlation analysis strategy, are combined to obtain the risk analysis results related to the target program (including the first risk analysis result and the second risk analysis result). Compared with the method of obtaining the risk analysis results of the application program by only using the static analysis method in the prior art, this method can not only analyze the target program from multiple dimensions, but also capture the dynamic behavior of the target program, thereby improving the reliability of the risk analysis results related to the target program.

[0044] In some optional implementations, step S101, i.e., “obtaining a plurality of features to be analyzed based on the target program”, may include:

[0045] Decompile the target program to obtain the code decompilation result;

[0046] Cut the code decompilation results to obtain multiple code fragments to be analyzed;

[0047] Based on multiple code snippets to be analyzed, multiple features to be analyzed are obtained.

[0048] The decompilation result may include multiple code function blocks, where each of the multiple code function blocks can implement a specific code function (eg, data processing, network request, etc.).

[0049] In addition, it is understood that in the embodiments of the present disclosure, multiple code snippets to be analyzed may correspond one-to-one to multiple code function blocks. Based on this, in one example, a preset reverse engineering tool may be used to decompile the target program to obtain a code decompilation result, and the code decompilation result may be analyzed to obtain multiple code function blocks. The code decompilation result may then be cleaned and cut based on the position of each of the multiple code function blocks in the code decompilation result to obtain multiple code snippets to be analyzed that correspond one-to-one to the multiple code function blocks. Finally, multiple features to be analyzed may be generated that include the multiple code snippets to be analyzed.

[0050] Through the above method, in the embodiment of the present disclosure, the target program can be decompiled to obtain the code decompilation result, and the code decompilation result can be segmented to obtain multiple code fragments to be analyzed. Then, based on the multiple code fragments to be analyzed, multiple features to be analyzed can be obtained. In other words, in the embodiment of the present disclosure, the multiple features to be analyzed can include multiple code fragments to be analyzed. In this way, each of the multiple code fragments to be analyzed can be used as an analysis object to reduce the analysis granularity of the target program, thereby further improving the reliability of the risk analysis results related to the target program.

[0051] In some optional implementations, step S101, i.e., “obtaining a plurality of features to be analyzed based on the target program”, may include:

[0052] Perform dynamic behavior detection on the target program to obtain multiple behaviors to be analyzed;

[0053] Based on the multiple behaviors to be analyzed, multiple features to be analyzed are obtained.

[0054] In one example, dynamic behavior detection can be performed on the target program in a sandbox environment or a virtual machine to obtain multiple behaviors to be analyzed. Specifically, the target program can be dynamically detected through a proxy packet capture tool and / or a hook tool (for example, Frida, Xposed, etc.) to obtain multiple behaviors to be analyzed. In another example, dynamic behavior detection can be performed on the target program using detection confrontation technology to obtain multiple behaviors to be analyzed. In combination with these two examples, in the embodiments of the present disclosure, dynamic behavior detection can be performed on the target program using a proxy packet capture tool and / or a hook tool that uses detection confrontation technology to obtain multiple behaviors to be analyzed.

[0055] Based on the above, it can be understood that in the embodiments of the present disclosure, the detection and countermeasure technology may include a proxy packet capture detection and countermeasure technology and / or a hook tool detection and countermeasure technology.

[0056] In one example, the proxy packet capture detection countermeasure technology can be used to indicate: integrating support for network traffic management tools (e.g., Iptables) in the target program's operating system (e.g., when the target program is an APK, the target program's operating system can be the Android system), so as to perform proxy settings at the operating system level, and call the network traffic management tool through a programming interface, and then add corresponding forwarding rules to achieve traffic forwarding, thereby performing dynamic behavior detection on the target program and obtaining multiple behaviors to be analyzed. In this way, compared with the traditional proxy packet capture detection technology, the proxy settings are converted from the application layer to the operating system level, making the dynamic behavior detection of the target program more secretive and not being detected by the target program (generally speaking, when the target program realizes that it is in a detected state, it may choose not to trigger risky behaviors temporarily to avoid detection), thereby increasing the difficulty of detecting and avoiding risky behaviors, that is, increasing the possibility of risky behaviors being exposed.

[0057] In one example, the hook tool detection countermeasure technology can be used to indicate: when the target program is subjected to dynamic behavior detection through the hook tool, the detection traces are quickly erased. For example, code obfuscation technology, memory protection mechanism, timely self-cleaning mechanism, etc. can be used to quickly erase the detection traces. In a specific example, a hook tool can be used on the key execution path of the target program to intercept its key dynamic behavior to achieve the purpose of dynamic behavior detection of the target program. Among them, the key dynamic behavior may include network request behavior, file operation behavior, process management behavior, system call behavior, etc. In this way, the dynamic behavior detection of the target program can also be made more secretive without the target program noticing, thereby increasing the difficulty of evading the detection of risky behaviors, that is, increasing the possibility of exposing risky behaviors.

[0058] In addition, it should be noted that in the embodiments of the present disclosure, in order to prevent the target program from evading detection of the system environment of the running system (for example, when the first electronic device is in the system debugging state, the target program may detect through the application programming interface (API) of its running system that the first electronic device is in the system debugging state, and choose not to trigger risky behavior temporarily to avoid detection), the running environment of the running system can also be customized to disguise the system debugging state. For example, the system debugging state can be disguised as a debugging state that is not started, so that the target program mistakenly believes that the system environment of the running system is in a safe state, thereby triggering risky behavior to increase the possibility of exposure of risky behavior.

[0059] Furthermore, in the embodiment of the present disclosure, after obtaining a plurality of behaviors to be analyzed, a plurality of features to be analyzed may be obtained based on the plurality of behaviors to be analyzed. For example, a plurality of features to be analyzed may be generated including the plurality of behaviors to be analyzed.

[0060] Through the above approach, in the disclosed embodiments, dynamic behavior detection can be performed on the target program to obtain multiple behaviors to be analyzed, and based on these multiple behaviors to be analyzed, multiple features to be analyzed can be obtained. That is, in the disclosed embodiments, the multiple features to be analyzed can include multiple behaviors to be analyzed. In this way, each of the multiple behaviors to be analyzed can then be used as an analysis target to reduce the granularity of the target program's analysis, thereby further improving the reliability of the risk analysis results related to the target program.

[0061] The embodiment of the present disclosure provides a program analysis method, which can be applied to a second electronic device. The second electronic device can be a service device, such as a server or other similar computing device. Figure 2 The flowchart shown in the figure illustrates a program analysis method provided by an embodiment of the present disclosure. It should be noted that although a logical order is shown in the flowchart, in some cases, the steps shown or described in the flowchart may also be performed in other orders.

[0062] Step S201: Acquire multiple features to be analyzed of the target program.

[0063] The target program can be any application package to be analyzed, such as an APK. The multiple features to be analyzed can include multiple code snippets to be analyzed and / or multiple behaviors to be analyzed based on the target program. The multiple behaviors to be analyzed can be dynamic behaviors captured during the runtime of the target program, specifically network request behaviors, file operation behaviors, process management behaviors, system call behaviors, etc., which are not described in detail in the present embodiment.

[0064] Furthermore, in the embodiment of the present disclosure, obtaining the multiple features to be analyzed of the target program may be receiving the multiple features to be analyzed sent by the first electronic device.

[0065] Step S202 : performing risk analysis on the multiple features to be analyzed by using a static feature comparison strategy and / or a dynamic behavior detection strategy to obtain a first risk analysis result for the multiple features to be analyzed.

[0066] Among them, the static feature comparison strategy can be used to instruct the analysis of multiple code snippets to be analyzed included in the multiple features to be analyzed, and obtain an overall analysis result for the multiple code snippets to be analyzed, which is used as the first type of analysis result for the multiple features to be analyzed; the dynamic behavior detection strategy can be used to instruct the analysis of multiple behaviors to be analyzed included in the multiple features to be analyzed, and obtain an overall analysis result for the multiple behaviors to be analyzed, which is used as the second type of analysis result for the multiple features to be analyzed. After obtaining the first type of analysis result and the second type of analysis result, a first risk analysis result for the multiple features to be analyzed can be obtained based on the first type of analysis result and the second type of analysis result.

[0067] Step S203: Perform risk analysis on the unknown behavior using a behavior correlation analysis strategy to obtain a second risk analysis result for the unknown behavior.

[0068] Among them, the behavior correlation analysis strategy can be used to instruct the correlation comparison of the unknown behavior with multiple first known risk behaviors to obtain a second risk analysis result for the unknown behavior; the unknown behavior is determined from multiple features to be analyzed based on the first risk analysis result.

[0069] In addition, in an embodiment of the present disclosure, when the first risk analysis result is used to characterize which of the multiple code fragments to be analyzed included in the multiple features to be analyzed are risky code fragments and which are non-risky code fragments, and to characterize which of the multiple behaviors to be analyzed included in the multiple features to be analyzed are risky behaviors and which are non-risky behaviors, the unknown behavior can be each of the multiple behaviors to be analyzed that is characterized as a non-risk behavior by the first risk analysis result.

[0070] Exemplarily, the multiple behaviors to be analyzed include behavior A1 to be analyzed, behavior A2 to be analyzed, behavior A3 to be analyzed, behavior A4 to be analyzed, and behavior A5 to be analyzed. Moreover, the first risk analysis result characterizes that among behavior A1 to be analyzed, behavior A2 to be analyzed, behavior A3 to be analyzed, behavior A4 to be analyzed, and behavior A5 to be analyzed, behavior A1 to be analyzed, behavior A2 to be analyzed, and behavior A3 to be analyzed are risk behaviors, and behavior A4 to be analyzed and behavior A5 to be analyzed are non-risk behaviors. Then, the unknown behavior can be each of the behaviors to be analyzed among behavior A1 to be analyzed, behavior A2 to be analyzed, and behavior A3 to be analyzed.

[0071] By adopting the program analysis method provided by the embodiment of the present disclosure, a plurality of features to be analyzed of the target program can be obtained, and risk analysis can be performed on the plurality of features to be analyzed through a static feature comparison strategy and / or a dynamic behavior detection strategy to obtain a first risk analysis result for the plurality of features to be analyzed, and then a risk analysis can be performed on the unknown behavior (the unknown behavior is determined from the plurality of features to be analyzed based on the first risk analysis result) through a behavior correlation analysis strategy to obtain a second risk analysis result for the unknown behavior. That is to say, in the embodiment of the present disclosure, the static feature comparison strategy and / or the dynamic behavior detection strategy, as well as the correlation analysis strategy, are combined to obtain risk analysis results related to the target program (including a first risk analysis result and a second risk analysis result). Compared with the prior art method of only using static analysis to obtain risk analysis results of an application program, this method can not only analyze the target program from multiple dimensions, but also capture the dynamic behavior of the target program, thereby improving the reliability of the risk analysis results related to the target program.

[0072] In some optional embodiments, step S202, i.e., "performing risk analysis on the multiple features to be analyzed using a static feature comparison strategy and / or a dynamic behavior detection strategy to obtain a first risk analysis result for the multiple features to be analyzed" may include:

[0073] Through the static feature comparison strategy, risk analysis is performed on multiple features to be analyzed, and the first-class analysis results for multiple features to be analyzed are obtained;

[0074] Through the dynamic behavior detection strategy, risk analysis is performed on multiple features to be analyzed, and the second type of analysis results for multiple features to be analyzed are obtained;

[0075] Based on the first type of analysis results and the second type of analysis results, a first risk analysis result for the plurality of features to be analyzed is obtained.

[0076] As previously mentioned, in the embodiments of the present disclosure, the multiple features to be analyzed may include multiple code snippets to be analyzed. Based on this, in one example, "performing a risk analysis on the multiple features to be analyzed using a static feature comparison strategy to obtain a first-class analysis result for the multiple features to be analyzed" may include:

[0077] Each of the multiple code fragments to be analyzed is used as a target code fragment, and features of the target code fragment are compared with multiple known risk code fragments to obtain a single fragment analysis result for the target code fragment;

[0078] Based on the single fragment analysis results, an overall analysis result for the multiple code fragments to be analyzed is obtained as a first-type analysis result for the multiple features to be analyzed.

[0079] Among them, multiple known risk code snippets can be stored in a risk code database included in the risk knowledge base; the analysis results of a single snippet can be used to characterize whether the target code snippet is a risk code snippet; the first type of analysis results can be used to characterize which of the multiple code snippets to be analyzed are risk code snippets and which are non-risk code snippets.

[0080] In addition, in the embodiment of the present disclosure, respectively comparing the characteristics of the target code fragment with multiple known risk code fragments can be respectively comparing the similarity of the target code fragment with multiple known risk code fragments. Based on this, in a specific example, after taking each of the multiple code fragments to be analyzed as the target code fragment, the target code fragment can be converted into a target code vector using an embedded model, and the multiple known risk code fragments can be converted one by one into multiple known risk code vectors using an embedded model, and the target code vector can be respectively compared with the multiple known risk code vectors for similarity, and then, when there is a similar risk code vector with a high similarity (for example, the similarity is greater than a first preset similarity threshold; the first preset similarity threshold can be set according to actual application requirements) with the target code vector in the multiple known risk code vectors, a single fragment analysis result is obtained to characterize that the target code fragment belongs to a risk code fragment; or, when there is no similar risk code vector with a high similarity with the target code vector in the multiple known risk code vectors, a single fragment analysis result is obtained to characterize that the target code fragment does not belong to a risk code fragment.

[0081] It should be noted that in the above example, when the single fragment analysis result characterizes that the target code fragment belongs to a risk code fragment, the target code fragment can be treated as a new known risk code fragment and stored in the risk code database included in the risk knowledge base to update the risk code database, thereby improving the reliability of the first type of analysis results for multiple features to be analyzed.

[0082] In the above example, each of the multiple code snippets to be analyzed can be used as a target code snippet. The target code snippet can then be compared against multiple known risk code snippets for their features, resulting in a single-segment analysis result for the target code snippet. Based on the single-segment analysis results, an overall analysis result for the multiple code snippets to be analyzed can be obtained as the first-class analysis result for the multiple features to be analyzed. This process does not involve complex data processing logic, thus improving the execution efficiency of the program analysis method.

[0083] As previously mentioned, in the embodiments of the present disclosure, the multiple features to be analyzed may include multiple behaviors to be analyzed. Based on this, in one example, "performing a risk analysis on the multiple features to be analyzed using a dynamic behavior detection strategy to obtain a second type of analysis result for the multiple features to be analyzed" may include:

[0084] Taking each of the multiple behaviors to be analyzed as a target behavior, and comparing the characteristics of the target behavior with the multiple first known risk behaviors, to obtain a single behavior analysis result for the target behavior;

[0085] Based on the single behavior analysis result, an overall analysis result for multiple behaviors to be analyzed is obtained as a second type of analysis result for multiple features to be analyzed.

[0086] Among them, multiple first known risk behaviors can be stored in the risk behavior database included in the risk knowledge base; a single behavior analysis result can be used to characterize whether the target behavior is a risk behavior; the second type of analysis result can be used to characterize which of the multiple behaviors to be analyzed are risk behaviors and which are non-risk behaviors.

[0087] In addition, in the embodiment of the present disclosure, respectively comparing the characteristics of the target behavior with the multiple first known risk behaviors can be respectively comparing the similarity of the target behavior with the multiple first known risk behaviors. Based on this, in a specific example, after taking each of the multiple behaviors to be analyzed as the target behavior, the target behavior can be converted into a target behavior vector using an embedded model, and the multiple first known risk behaviors can be converted one-to-one into multiple known risk behavior vectors using an embedded model, and the target behavior vector can be respectively compared with the multiple known risk behavior vectors for similarity, and then, when there is a similar risk behavior vector with a high similarity (for example, the similarity is greater than a second preset similarity threshold; the second preset similarity threshold can be set according to actual application requirements) with the target behavior vector in the multiple known risk behavior vectors, a single behavior analysis result is obtained for characterizing that the target behavior belongs to a risk behavior; or, when there is no similar risk behavior vector with a high similarity with the target behavior in the multiple known risk behavior vectors, a single behavior analysis result is obtained for characterizing that the target behavior does not belong to a risk behavior.

[0088] It should be noted that in the above example, when a single behavior analysis result characterizes that the target behavior is a risky behavior, the target behavior can be taken as a new first known risk behavior and stored in the risk behavior database included in the risk knowledge base to update the risk behavior database, thereby improving the reliability of the second type of analysis results for multiple features to be analyzed.

[0089] In the above example, each of the multiple behaviors to be analyzed can be used as a target behavior, and the characteristics of the target behavior can be compared with the characteristics of the multiple first known risk behaviors to obtain a single behavior analysis result for the target behavior. Based on the single behavior analysis result, an overall analysis result for the multiple behaviors to be analyzed is obtained as a second type of analysis result for the multiple characteristics to be analyzed. This process does not involve complex data processing logic, thereby improving the execution efficiency of the program analysis method.

[0090] After obtaining the first type of analysis results and the second type of analysis results, a first risk analysis result for multiple features to be analyzed can be obtained based on the first type of analysis results and the second type of analysis results. In one example, the first type of analysis results and the second type of analysis results can be used together as the first risk analysis result for each feature to be analyzed. Based on this, it can be understood that in the embodiment of the present disclosure, the first risk analysis result can be used to characterize which of the multiple code fragments to be analyzed included in the multiple features to be analyzed are risky code fragments and which are non-risky code fragments, and to characterize which of the multiple behaviors to be analyzed included in the multiple features to be analyzed are risky behaviors and which are non-risky behaviors.

[0091] Through the above methods, in the embodiment of the present disclosure, a risk analysis can be performed on multiple features to be analyzed through a static feature comparison strategy to obtain a first type of analysis result for the multiple features to be analyzed, and a risk analysis can be performed on multiple features to be analyzed through a dynamic behavior detection strategy to obtain a second type of analysis result for the multiple features to be analyzed, and based on the first type of analysis result and the second type of analysis result, a first risk analysis result for the multiple features to be analyzed is obtained. That is to say, in the embodiment of the present disclosure, the static feature comparison strategy and the dynamic behavior detection strategy are combined to obtain the risk analysis result (including the first risk analysis result) related to the target program. Compared with the method of obtaining the risk analysis result of the application program by only using the static analysis method in the prior art, this method can not only analyze the target program from multiple dimensions, but also capture the dynamic behavior of the target program, thereby improving the reliability of the risk analysis result related to the target program.

[0092] In some optional implementations, step S203, i.e., "performing a risk analysis on the unknown behavior using a behavior correlation analysis strategy to obtain a second risk analysis result for the unknown behavior," may include:

[0093] taking each first known risk behavior among the plurality of first known risk behaviors as a first behavior to be compared, to obtain first behavior association information of the first behavior to be compared;

[0094] Obtaining second behavior association information of an unknown behavior;

[0095] By comparing the correlation between the first behavior correlation information and the second behavior correlation information, a second risk analysis result for the unknown behavior is obtained.

[0096] The first behavior association information may include the external behavior association information and internal behavior pattern of the first behavior to be compared; the second behavior association information may include the external behavior association information and internal behavior pattern of the unknown behavior; and the second risk analysis result may be used to characterize whether the unknown behavior is a risky behavior. Here, the external behavior association information may include: a preset number of external behaviors that are positionally associated with the current behavior subject (e.g., the first behavior to be compared or the unknown behavior), as well as the positional association relationship between the current behavior subject and the preset number of external behaviors; the internal behavior pattern may include: the internal behavior actions of the current behavior subject.

[0097] For example, if the preset number is 4, then for a current subject behavior, its external behavior association information can be represented as: previous association behavior B1 - previous association behavior B2 - current subject - next association behavior B3 - next association behavior B4. Here, previous association behavior B1 is located before the current subject and is separated from the current subject by one external behavior; previous association behavior B2 is located before the current subject and is adjacent to the current subject; next association behavior B3 is located after the current subject and is adjacent to the current subject; and next association behavior B4 is located after the current subject and is separated from the current subject by one external behavior.

[0098] For example, for a current subject behavior, its internal behavior pattern may include:

[0099] Internal action C1: Requesting auxiliary service function after the target program is started;

[0100] Internal behavior action C2: There is an automated click framework file in the target program's system file "system / data / tmp / ";

[0101] Internal behavior action C3: An exception is found in the touch event parameters of the target program.

[0102] In one example, “obtaining a second risk analysis result for the unknown behavior by comparing the first behavior association information with the second behavior association information” may include:

[0103] By comparing the correlation between the first behavior correlation information and the second behavior correlation information, a preliminary analysis result for the unknown behavior is obtained;

[0104] When the initial analysis result indicates that the unknown behavior is a risky behavior, the initial analysis result is used as the second risk analysis result for the unknown behavior; or, when the initial analysis result indicates that the unknown behavior is a non-risky behavior, the large language model is used to obtain the second risk analysis result for the unknown behavior.

[0105] Among them, comparing the correlation between the first behavior association information and the second behavior association information can be comparing the similarity between the first behavior association information and the second behavior association information. Based on this, in a specific example, the first behavior association information can be converted into a first behavior association vector using an embedded model, and the second behavior association information can be converted into a second behavior association vector using an embedded model, and the first behavior association vector and the second behavior association vector can be compared for similarity, and then, when the first behavior association vector and the second behavior association vector have a high similarity (for example, the similarity is greater than a third preset similarity threshold; the third preset similarity threshold can be set according to actual application requirements), a preliminary analysis result is obtained for characterizing that the unknown behavior belongs to a risky behavior; or, when the first behavior association vector and the second behavior association vector do not have a high similarity, a preliminary analysis result is obtained for characterizing that the unknown behavior does not belong to a risky behavior.

[0106] It should be noted that in the above example, when the second risk analysis result (specifically, the initial analysis result) characterizes the unknown behavior as a risky behavior, the unknown behavior can be treated as a new first known risky behavior and stored in the risk behavior database included in the risk knowledge base to update the risk behavior database, thereby improving the reliability of the initial analysis result for the unknown behavior; when the second risk analysis result (specifically, the initial analysis result) characterizes the unknown behavior as a non-risky behavior, the unknown behavior can continue to be judged, for example, a large language model can be used to obtain a second risk analysis result for the unknown behavior. In a specific example, "using a large language model to obtain a second risk analysis result for the unknown behavior" may include:

[0107] Using large language models, multiple second-known risk behaviors are identified;

[0108] taking each second known risk behavior among the plurality of second known risk behaviors as a second behavior to be compared, to obtain third behavior association information of the second behavior to be compared;

[0109] By comparing the correlation between the second behavior correlation information and the third behavior correlation information, a second risk analysis result for the unknown behavior is obtained.

[0110] The large language model can be a pre-trained neural network model that possesses universal and extensive language knowledge, world knowledge, and expertise in various fields. In one example, the large language model can be an autoregressive generative model based on a Transformer architecture. Based on this, it can be understood that in the embodiments of the present disclosure, the large language model can be used to determine multiple second known risk behaviors based on its extensive expertise in various fields (e.g., expertise in the field of information technology).

[0111] After obtaining multiple second known risk behaviors, the large language model can be used to use each of the multiple second known risk behaviors as a second behavior to be compared, thereby obtaining third behavior association information for the second behavior to be compared. A second risk analysis result for the unknown behavior can be obtained by performing a correlation comparison between the second behavior association information and the third behavior association information. The third behavior association information can include external behavior association information and internal behavior patterns of the second behavior to be compared. The second risk analysis result is used to characterize whether the unknown behavior is a risky behavior.

[0112] In addition, it should be noted that in the embodiment of the present disclosure, in order to improve the reliability of the second risk analysis result for the unknown behavior obtained using the large language model, a prompt word (Prompt) can be designed for the large language model to indicate how the large language model obtains the second risk analysis result for the unknown behavior. Specifically, it can be used to instruct the large language model to use each second known risk behavior in multiple second known risk behaviors as the second behavior to be compared, to obtain the third behavior association information of the second behavior to be compared, and to obtain the second risk analysis result for the unknown behavior by performing a correlation comparison on the second behavior association information and the third behavior association information. For example, the prompt word can be, "You are an expert in black industry chain analysis. I will give you an analysis example. Please follow this analysis example and tell me whether the unknown behavior is a risky behavior", and provide this analysis example to the large language model. For example, there is a first behavior to be compared D1 and an unknown behavior D2. By performing a correlation comparison on the first behavior association information of the first behavior to be compared D1 and the second behavior association information of the unknown behavior D2, an initial analysis result is obtained to characterize that the unknown behavior is a risky behavior. Then, this analysis example can be the specific process of obtaining the initial analysis results related to the first behavior to be compared D1 and the unknown behavior D2, and the analysis example can be stored in the rule example database included in the risk database after the initial analysis results related to the first behavior to be compared D1 and the unknown behavior D2 are obtained.

[0113] Through the above method, in the embodiment of the present disclosure, each first known risk behavior among multiple first known risk behaviors can be used as the first behavior to be compared to obtain first behavior association information of the first behavior to be compared, and obtain second behavior association information of the unknown behavior, and by performing a correlation comparison between the first behavior association information and the second behavior association information, a second risk analysis result for the unknown behavior is obtained. That is to say, in the embodiment of the present disclosure, deeper features of the target program (specifically, the unknown behavior in the target program) can also be excavated through the correlation comparison of the behavior association information, and risk analysis results related to the target program (including the second risk analysis result) can be obtained accordingly, thereby further improving the reliability of the risk analysis results.

[0114] In addition, in the embodiment of the present disclosure, in the process of "obtaining a second risk analysis result for the unknown behavior by performing a correlation comparison on the first behavior association information and the second behavior association information", specifically, a primary analysis result for the unknown behavior is obtained by performing a correlation comparison on the first behavior association information and the second behavior association information, and when the primary analysis result characterizes that the unknown behavior is a risky behavior, the primary analysis result is used as the second risk analysis result for the unknown behavior; or, when the primary analysis result characterizes that the unknown behavior is a non-risky behavior, a large language model is used to obtain a second risk analysis result for the unknown behavior. That is to say, in the embodiment of the present disclosure, a large language model will also be used to analyze the unknown behavior, and based on the powerful knowledge reserve capacity and data analysis capacity of the large language model, the reliability of the risk analysis results (including the second risk analysis results) related to the target program can be further ensured.

[0115] The following will be combined Figure 3 and 4 , the integrity process of a program analysis method provided by an embodiment of the present disclosure is described.

[0116] First, it should be noted that before executing the program analysis method provided by the embodiments of this disclosure, a risk knowledge base must be constructed. This risk knowledge base can include a risk code database and a risk behavior database. The risk code database can be used to store multiple known risk code snippets, each of which can be vectorized data; the risk behavior database can be used to store multiple first known risk behaviors, each of which can be vectorized data.

[0117] Thereafter, on the first electronic device side (for example, the terminal device side), the following operations may be performed:

[0118] (1) Obtain the target program.

[0119] The target program may be any application package that needs to be analyzed, such as APK.

[0120] (2) Decompiling the target program to obtain a code decompilation result, segmenting the code decompilation result to obtain multiple code segments to be analyzed, and then sending the multiple code segments to be analyzed to a second electronic device (e.g., a service device).

[0121] The decompilation result may include multiple code function blocks, where each of the multiple code function blocks can implement a specific code function (eg, data processing, network request, etc.).

[0122] In addition, it is understood that in the embodiments of the present disclosure, multiple code snippets to be analyzed may correspond one-to-one to multiple code function blocks. Based on this, in one example, a preset reverse engineering tool may be used to decompile the target program to obtain a code decompilation result, and the code decompilation result may be analyzed to obtain multiple code function blocks. The code decompilation result may then be cleaned and cut based on the position of each of the multiple code function blocks in the code decompilation result to obtain multiple code snippets to be analyzed that correspond one-to-one to the multiple code function blocks. Finally, multiple features to be analyzed may be generated that include the multiple code snippets to be analyzed.

[0123] (3) Performing dynamic behavior detection on the target program to obtain multiple behaviors to be analyzed, and sending the multiple behaviors to be analyzed to a second electronic device (eg, a service device).

[0124] In one example, dynamic behavior detection can be performed on the target program in a sandbox environment or a virtual machine to obtain multiple behaviors to be analyzed. Specifically, the target program can be dynamically detected through a proxy packet capture tool and / or a hook tool (for example, Frida, Xposed, etc.) to obtain multiple behaviors to be analyzed. In another example, dynamic behavior detection can be performed on the target program using detection confrontation technology to obtain multiple behaviors to be analyzed. In combination with these two examples, in the embodiments of the present disclosure, dynamic behavior detection can be performed on the target program using a proxy packet capture tool and / or a hook tool that uses detection confrontation technology to obtain multiple behaviors to be analyzed.

[0125] Based on the above, it can be understood that in the embodiments of the present disclosure, the detection and countermeasure technology may include a proxy packet capture detection and countermeasure technology and / or a hook tool detection and countermeasure technology.

[0126] In one example, the proxy packet capture detection countermeasure technology can be used to indicate: integrating support for network traffic management tools (e.g., Iptables) in the target program's operating system (e.g., when the target program is an APK, the target program's operating system can be the Android system), so as to perform proxy settings at the operating system level, and call the network traffic management tool through a programming interface, and then add corresponding forwarding rules to achieve traffic forwarding, thereby performing dynamic behavior detection on the target program and obtaining multiple behaviors to be analyzed. In this way, compared with the traditional proxy packet capture detection technology, the proxy settings are converted from the application layer to the operating system level, making the dynamic behavior detection of the target program more secretive and not being detected by the target program (generally speaking, when the target program realizes that it is in a detected state, it may choose not to trigger risky behaviors temporarily to avoid detection), thereby increasing the difficulty of detecting and avoiding risky behaviors, that is, increasing the possibility of risky behaviors being exposed.

[0127] In one example, the hook tool detection countermeasure technology can be used to indicate: when the target program is subjected to dynamic behavior detection through the hook tool, the detection traces are quickly erased. For example, code obfuscation technology, memory protection mechanism, timely self-cleaning mechanism, etc. can be used to quickly erase the detection traces. In a specific example, a hook tool can be used on the key execution path of the target program to intercept its key dynamic behavior to achieve the purpose of dynamic behavior detection of the target program. Among them, the key dynamic behavior may include network request behavior, file operation behavior, process management behavior, system call behavior, etc. In this way, the dynamic behavior detection of the target program can also be made more secretive without the target program noticing, thereby increasing the difficulty of evading the detection of risky behaviors, that is, increasing the possibility of exposing risky behaviors.

[0128] In addition, it should be noted that in the embodiments of the present disclosure, in order to prevent the target program from evading detection of the system environment of the running system (for example, when the first electronic device is in a system debugging state, the target program may detect through the API of its running system that the first electronic device is in a system debugging state, and choose not to trigger risky behavior temporarily to avoid detection), the running environment of the running system can also be customized to disguise the system debugging state. For example, the system debugging state can be disguised as a debugging state that is not started, so that the target program mistakenly believes that the system environment of the running system is in a safe state, thereby triggering risky behavior to increase the possibility of exposure of risky behavior.

[0129] The above can be achieved based on the decompilation tools (including code decompilation unit, code cleaning unit, code cutting unit, etc.) and the operating environment (including detection and countermeasure technology, proxy packet capture tools, hook tools, etc.) provided by the data monitoring layer in the program analysis framework.

[0130] Next, on the second electronic device side (for example, the service device side), the following operations may be performed:

[0131] (4) Receive multiple features to be analyzed sent by the first electronic device.

[0132] The multiple features to be analyzed may include multiple code snippets to be analyzed and multiple behaviors to be analyzed.

[0133] (5) Through the static feature comparison strategy, risk analysis is performed on multiple features to be analyzed, and the first type of analysis results for multiple features to be analyzed are obtained.

[0134] In one example, “performing risk analysis on multiple features to be analyzed using a static feature comparison strategy to obtain first-class analysis results for the multiple features to be analyzed” may include:

[0135] Each of the multiple code fragments to be analyzed is used as a target code fragment, and features of the target code fragment are compared with multiple known risk code fragments to obtain a single fragment analysis result for the target code fragment;

[0136] Based on the single fragment analysis results, an overall analysis result for the multiple code fragments to be analyzed is obtained as a first-type analysis result for the multiple features to be analyzed.

[0137] Among them, multiple known risk code snippets can be stored in a risk code database included in the risk knowledge base; the analysis results of a single snippet can be used to characterize whether the target code snippet is a risk code snippet; the first type of analysis results can be used to characterize which of the multiple code snippets to be analyzed are risk code snippets and which are non-risk code snippets.

[0138] In addition, in the embodiment of the present disclosure, respectively performing feature comparison on the target code segment with multiple known risk code segments can be respectively performing similarity comparison on the target code segment with multiple known risk code segments. Based on this, in a specific example, after taking each of the multiple code segments to be analyzed as the target code segment, the target code segment can be converted into a target code vector using an embedded model, and the multiple known risk code segments can be converted one-to-one into multiple known risk code vectors using an embedded model, and the target code vector can be respectively compared with the multiple known risk code vectors for similarity, and then, when there is a similar risk code vector with a high similarity (for example, the similarity is greater than a first preset similarity threshold; the first preset similarity threshold can be set according to actual application requirements) with the target code vector in the multiple known risk code vectors, a single segment analysis result is obtained for characterizing that the target code segment belongs to a risk code segment; or, when there is no similar risk code vector with a high similarity with the target code vector in the multiple known risk code vectors, a single segment analysis result is obtained for characterizing that the target code segment does not belong to a risk code segment.

[0139] It should be noted that in the above example, when the single fragment analysis result characterizes that the target code fragment belongs to a risk code fragment, the target code fragment can be treated as a new known risk code fragment and stored in the risk code database included in the risk knowledge base to update the risk code database, thereby improving the reliability of the first type of analysis results for multiple features to be analyzed.

[0140] (6) Through the dynamic behavior detection strategy, risk analysis is performed on multiple features to be analyzed, and the second type of analysis results for multiple features to be analyzed are obtained.

[0141] In one example, “performing risk analysis on multiple features to be analyzed using a dynamic behavior detection strategy to obtain second-type analysis results for the multiple features to be analyzed” may include:

[0142] Taking each of the multiple behaviors to be analyzed as a target behavior, and comparing the characteristics of the target behavior with the multiple first known risk behaviors, to obtain a single behavior analysis result for the target behavior;

[0143] Based on the single behavior analysis result, an overall analysis result for multiple behaviors to be analyzed is obtained as a second type of analysis result for multiple features to be analyzed.

[0144] Among them, multiple first known risk behaviors can be stored in the risk behavior database included in the risk knowledge base; a single behavior analysis result can be used to characterize whether the target behavior is a risk behavior; the second type of analysis result can be used to characterize which of the multiple behaviors to be analyzed are risk behaviors and which are non-risk behaviors.

[0145] In addition, in the embodiment of the present disclosure, respectively comparing the characteristics of the target behavior with the multiple first known risk behaviors can be respectively comparing the similarity of the target behavior with the multiple first known risk behaviors. Based on this, in a specific example, after taking each of the multiple behaviors to be analyzed as the target behavior, the target behavior can be converted into a target behavior vector using an embedded model, and the multiple first known risk behaviors can be converted one-to-one into multiple known risk behavior vectors using an embedded model, and the target behavior vector can be respectively compared with the multiple known risk behavior vectors for similarity, and then, when there is a similar risk behavior vector with a high similarity (for example, the similarity is greater than a second preset similarity threshold; the second preset similarity threshold can be set according to actual application requirements) with the target behavior vector in the multiple known risk behavior vectors, a single behavior analysis result is obtained for characterizing that the target behavior belongs to a risk behavior; or, when there is no similar risk behavior vector with a high similarity with the target behavior in the multiple known risk behavior vectors, a single behavior analysis result is obtained for characterizing that the target behavior does not belong to a risk behavior.

[0146] It should be noted that in the above example, when a single behavior analysis result characterizes that the target behavior is a risky behavior, the target behavior can be taken as a new first known risk behavior and stored in the risk behavior database included in the risk knowledge base to update the risk behavior database, thereby improving the reliability of the second type of analysis results for multiple features to be analyzed.

[0147] (7) Based on the first type of analysis results and the second type of analysis results, a first risk analysis result for the plurality of features to be analyzed is obtained.

[0148] In one example, the first type of analysis results and the second type of analysis results can be used together as the first risk analysis result for each feature to be analyzed. Based on this, it can be understood that in the embodiments of the present disclosure, the first risk analysis result can be used to characterize which of the multiple code snippets to be analyzed included in the multiple features to be analyzed are risky code snippets and which are non-risky code snippets, and to characterize which of the multiple behaviors to be analyzed included in the multiple features to be analyzed are risky behaviors and which are non-risky behaviors.

[0149] (8) Each first known risk behavior among the multiple first known risk behaviors is used as a first behavior to be compared, so as to obtain first behavior association information of the first behavior to be compared.

[0150] The first behavior association information may include external behavior association information and internal behavior patterns of the first behavior to be compared. Here, the external behavior association information may include: a preset number of external behaviors that are positionally associated with the current behavior subject (e.g., the first behavior to be compared), and the positional association relationship between the current behavior subject and the preset number of external behaviors; the internal behavior pattern may include: the internal behavior actions of the current behavior subject.

[0151] (9) Obtain the second behavior association information of the unknown behavior.

[0152] The unknown behavior may be each of the behaviors to be analyzed characterized as a non-risk behavior by the first risk analysis result among the multiple behaviors to be analyzed; the second behavior association information may include external behavior association information and internal behavior patterns of the unknown behavior.

[0153] (10) By comparing the correlation between the first behavior correlation information and the second behavior correlation information, a second risk analysis result for the unknown behavior is obtained.

[0154] The second risk analysis result can be used to characterize whether the unknown behavior is a risky behavior.

[0155] In one example, “obtaining a second risk analysis result for the unknown behavior by comparing the first behavior association information with the second behavior association information” may include:

[0156] By comparing the correlation between the first behavior correlation information and the second behavior correlation information, a preliminary analysis result for the unknown behavior is obtained;

[0157] When the initial analysis result indicates that the unknown behavior is a risky behavior, the initial analysis result is used as the second risk analysis result for the unknown behavior; or, when the initial analysis result indicates that the unknown behavior is a non-risky behavior, the large language model is used to obtain the second risk analysis result for the unknown behavior.

[0158] Among them, comparing the correlation between the first behavior association information and the second behavior association information can be comparing the similarity between the first behavior association information and the second behavior association information. Based on this, in a specific example, the first behavior association information can be converted into a first behavior association vector using an embedded model, and the second behavior association information can be converted into a second behavior association vector using an embedded model, and the first behavior association vector and the second behavior association vector can be compared for similarity, and then, when the first behavior association vector and the second behavior association vector have a high similarity (for example, the similarity is greater than a third preset similarity threshold; the third preset similarity threshold can be set according to actual application requirements), a preliminary analysis result is obtained for characterizing that the unknown behavior belongs to a risky behavior; or, when the first behavior association vector and the second behavior association vector do not have a high similarity, a preliminary analysis result is obtained for characterizing that the unknown behavior does not belong to a risky behavior.

[0159] It should be noted that in the above example, when the second risk analysis result (specifically, the initial analysis result) characterizes the unknown behavior as a risky behavior, the unknown behavior can be treated as a new first known risky behavior and stored in the risk behavior database included in the risk knowledge base to update the risk behavior database, thereby improving the reliability of the initial analysis result for the unknown behavior; when the second risk analysis result (specifically, the initial analysis result) characterizes the unknown behavior as a non-risky behavior, the unknown behavior can continue to be judged, for example, a large language model can be used to obtain a second risk analysis result for the unknown behavior. In a specific example, "using a large language model to obtain a second risk analysis result for the unknown behavior" may include:

[0160] Using large language models, multiple second-known risk behaviors are identified;

[0161] taking each second known risk behavior among the plurality of second known risk behaviors as a second behavior to be compared, to obtain third behavior association information of the second behavior to be compared;

[0162] By comparing the correlation between the second behavior correlation information and the third behavior correlation information, a second risk analysis result for the unknown behavior is obtained.

[0163] In the disclosed embodiment, a large language model can be used to determine multiple second known risk behaviors based on its massive professional knowledge in various fields (for example, professional knowledge in the field of information technology).

[0164] After obtaining multiple second known risk behaviors, the large language model can be used to use each of the multiple second known risk behaviors as a second behavior to be compared, thereby obtaining third behavior association information for the second behavior to be compared. A second risk analysis result for the unknown behavior can be obtained by performing a correlation comparison between the second behavior association information and the third behavior association information. The third behavior association information can include external behavior association information and internal behavior patterns of the second behavior to be compared. The second risk analysis result is used to characterize whether the unknown behavior is a risky behavior.

[0165] In addition, it should be noted that in the embodiment of the present disclosure, in order to improve the reliability of the second risk analysis result for the unknown behavior obtained using the large language model, a prompt word can be designed for the large language model to indicate how the large language model obtains the second risk analysis result for the unknown behavior. Specifically, it can be used to instruct the large language model to use each second known risk behavior in multiple second known risk behaviors as the second behavior to be compared, to obtain the third behavior association information of the second behavior to be compared, and to obtain the second risk analysis result for the unknown behavior by performing a correlation comparison on the second behavior association information and the third behavior association information. For example, the prompt word can be, "You are an expert in black industry chain analysis. I will give you an analysis example. Please follow this analysis example and tell me whether the unknown behavior is a risky behavior", and provide this analysis example to the large language model. For example, there is a first behavior to be compared D1 and an unknown behavior D2. By performing a correlation comparison on the first behavior association information of the first behavior to be compared D1 and the second behavior association information of the unknown behavior D2, an initial analysis result is obtained to characterize that the unknown behavior is a risky behavior. Then, this analysis example can be a specific acquisition process of the initial analysis result related to the first behavior to be compared D1 and the unknown behavior D2, and the analysis example can be stored in the rule example database included in the risk database after the initial analysis result related to the first behavior to be compared D1 and the unknown behavior D2 is obtained. The second risk analysis result (specifically, the second risk analysis result obtained by the large language model) characterizes that the unknown behavior belongs to the risk behavior

[0166] It should also be noted that in the above specific example, when the second risk analysis result (specifically, the second risk analysis result obtained through the large language model) characterizes that the unknown behavior is a risky behavior, the unknown behavior can be verified through online verification to further confirm whether the unknown behavior is a risky behavior. When it is confirmed that the unknown behavior is a risky behavior, the unknown behavior can be used as a new first known risky behavior and stored in the risk behavior database included in the risk knowledge base to update the risk behavior database, thereby improving the reliability of the initial analysis results for the unknown behavior. Among them, online verification can be running the unknown behavior in an actual system environment to further confirm whether the unknown behavior is a risky behavior.

[0167] The above can be achieved based on the risk knowledge base (including the risk code database, risk behavior database and rule example database) and the large language model provided by the data analysis layer in the program analysis framework.

[0168] After completing the above steps, you can generate an analysis report for the target program. The analysis report may include:

[0169] (1) Risky code snippets and risky behaviors identified based on the risk knowledge base;

[0170] (2) Risk behaviors inferred through large language models and verified online;

[0171] (3) Update records of the risk knowledge base and recommendations for future defense strategies.

[0172] It should be noted that, in the embodiments of the present disclosure, the process of outputting the latest determined risk code snippets and risk behaviors, and the process of generating an analysis report for the target program can both be implemented based on the data output layer in the program analysis framework.

[0173] Finally, the program analysis method provided by the embodiment of the present disclosure has the following advantages:

[0174] (1) Improving the comprehensiveness of black industry chain attack identification

[0175] At present, the commonly used program analysis method is static analysis. In the embodiment of the present disclosure, a static feature comparison strategy and / or a dynamic behavior detection strategy, as well as a correlation analysis strategy, are combined to obtain risk analysis results related to the target program (including a first risk analysis result and a second risk analysis result). Compared with the prior art method of only using static analysis to obtain risk analysis results of the application program, this method can not only analyze the target program from multiple dimensions, but also capture the dynamic behavior of the target program, thereby improving the reliability of the risk analysis results related to the target program.

[0176] (2) Ability to infer unknown attacks

[0177] When faced with new, unknown attacks (i.e., unknown behaviors), existing program analysis methods often rely on manual analysis and expert judgment, resulting in slow response times. In the disclosed embodiments, a mechanism of large language model reasoning and knowledge enhancement (i.e., correlation comparison) is introduced, enabling program analysis methods to automatically infer new, unknown attacks. Specific advantages include:

[0178] a. Knowledge-enhanced inference: Through accumulated analysis examples, new and unknown attacks are regularly inferred to avoid blind guesses, making the risk analysis results related to the target program (specifically, the second risk analysis results obtained through the large language model) more reasonable.

[0179] b. Large-model reasoning: Based on the large-scale reasoning capabilities of deep learning models and combined with prompt word technology, it can quickly determine whether unknown behaviors are risky behaviors and then conduct online verification.

[0180] c. Data Flywheel: When a single snippet analysis result indicates that a target code snippet is a risky code snippet, the target code snippet can be treated as a new known risky code snippet and stored in the risk code database included in the risk knowledge base. When a single behavior analysis result indicates that a target behavior is a risky behavior, the target behavior can be treated as a new first known risky behavior and stored in the risk behavior database included in the risk knowledge base. When a second risk analysis result (specifically, the initial analysis result) indicates that an unknown behavior is a risky behavior, the unknown behavior can be treated as a new first known risky behavior and stored in the risk behavior database included in the risk knowledge base. When a second risk analysis result (specifically, the second risk analysis result obtained by a large language model) indicates that the unknown behavior is a risky behavior, and the unknown behavior is verified through online verification to further confirm that the unknown behavior is a risky behavior, the unknown behavior can be treated as a new first known risky behavior and stored in the risk behavior database included in the risk knowledge base. In this way, the risk database can form a closed loop of continuous self-optimization, making the program analysis method increasingly intelligent and more adaptable to new and unknown attacks.

[0181] (3) Enhance the ability to detect risky behaviors

[0182] Proxy packet capture tools and / or hook tools employing detection countermeasures perform dynamic behavior detection on target programs, generating multiple behaviors for analysis. This effectively prevents risky behaviors from evading detection, making dynamic behavior detection strategies more robust and ensuring that risky behaviors are fully exposed.

[0183] See also Figure 5 , which is a schematic diagram of an application scenario of a program analysis method provided by an embodiment of the present disclosure. The application analysis method can be applied to an electronic device. Here, the electronic device can be a first electronic device or a second electronic device. Specifically, the first electronic device can be a terminal device, specifically a conventional computer (desktop computer, laptop computer, etc.), a car computer, a tablet computer, a smartphone, a personal digital assistant, or other similar computing device; the second electronic device can be a service device.

[0184] Specifically, the first electronic device can be used to:

[0185] Based on the target program, multiple features to be analyzed are obtained.

[0186] Multiple features to be analyzed are sent to a service device; wherein the service device is used to perform risk analysis on the multiple features to be analyzed through a static feature comparison strategy and / or a dynamic behavior detection strategy to obtain a first risk analysis result for the multiple features to be analyzed, and is used to perform risk analysis on unknown behaviors through a behavior correlation analysis strategy to obtain a second risk analysis result for the unknown behaviors; the unknown behaviors are determined from the multiple features to be analyzed based on the first risk analysis result.

[0187] Specifically, the second electronic device can be used to:

[0188] Obtain multiple features to be analyzed of the target program;

[0189] Performing risk analysis on the multiple features to be analyzed using a static feature comparison strategy and / or a dynamic behavior detection strategy to obtain a first risk analysis result for the multiple features to be analyzed;

[0190] Through the behavior correlation analysis strategy, a risk analysis is performed on the unknown behavior to obtain a second risk analysis result for the unknown behavior; wherein the unknown behavior is determined from multiple features to be analyzed based on the first risk analysis result.

[0191] After obtaining the first risk analysis result and the second risk analysis result, they can be fed back to the first electronic device so that the first electronic device can perform effective risk management when running the target program again. They can also be applied to subsequent application upgrade operations. This embodiment of the present disclosure will not be elaborated on this.

[0192] It should be noted that, in the embodiments of the present disclosure, Figure 5 The scene diagram shown is only for illustration and not for limitation. Those skilled in the art can Figure 5 Various obvious changes and / or substitutions may be made to the examples, and the obtained technical solutions still fall within the scope of the disclosure of the embodiments of the present disclosure.

[0193] In order to better implement the program analysis method applied to the first electronic device, the embodiment of the present disclosure further provides a program analysis device 600, which can be integrated into the first electronic device. The first electronic device can be a terminal device, for example, a conventional computer (desktop computer, laptop computer, etc.), a car computer, a tablet computer, a smart phone, a personal digital assistant or other similar computing devices. Figure 6 The schematic structural block diagram shown illustrates a program analysis device 600 provided by the disclosed embodiment.

[0194] The program analysis device 600 includes:

[0195] The second feature acquisition unit 601 is used to obtain multiple features to be analyzed based on the target program;

[0196] The feature sending unit 602 is used to send multiple features to be analyzed to the service device; wherein the service device is used to perform risk analysis on the multiple features to be analyzed through a static feature comparison strategy and / or a dynamic behavior detection strategy to obtain a first risk analysis result for the multiple features to be analyzed, and is used to perform risk analysis on unknown behaviors through a behavior correlation analysis strategy to obtain a second risk analysis result for the unknown behaviors; the unknown behaviors are determined from the multiple features to be analyzed based on the first risk analysis result.

[0197] In some optional implementations, the second feature acquisition unit 601 is configured to:

[0198] Decompile the target program to obtain the code decompilation result;

[0199] Cut the code decompilation results to obtain multiple code fragments to be analyzed;

[0200] Based on multiple code snippets to be analyzed, multiple features to be analyzed are obtained.

[0201] In some optional implementations, the second feature acquisition unit 601 is configured to:

[0202] Perform dynamic behavior detection on the target program to obtain multiple behaviors to be analyzed;

[0203] Based on the multiple behaviors to be analyzed, multiple features to be analyzed are obtained.

[0204] In some optional implementations, the second feature acquisition unit 601 is configured to:

[0205] Detection and adversarial technology is used to perform dynamic behavior detection on the target program and obtain multiple behaviors to be analyzed.

[0206] In the embodiment of the present disclosure, the specific functions and examples of each unit in the program analysis device 600 can be found in the relevant descriptions of the corresponding steps in the aforementioned embodiment of the program analysis method applied to the first electronic device, and are not repeated here.

[0207] In order to better implement the program analysis method applied to the second electronic device, the embodiment of the present disclosure further provides a program analysis device 700, which can be integrated into the second electronic device. The second electronic device can be a service device, such as a server or other similar computing device. Figure 7 The schematic structural block diagram shown illustrates a program analysis device 700 provided by the disclosed embodiment.

[0208] The program analysis device 700 includes:

[0209] A first feature acquisition unit 701 is used to acquire multiple features to be analyzed of the target program;

[0210] A first risk analysis unit 702 is configured to perform risk analysis on a plurality of features to be analyzed using a static feature comparison strategy and / or a dynamic behavior detection strategy to obtain a first risk analysis result for the plurality of features to be analyzed;

[0211] The second risk analysis unit 703 is used to perform risk analysis on the unknown behavior through the behavior correlation analysis strategy to obtain a second risk analysis result for the unknown behavior; wherein the unknown behavior is determined from multiple features to be analyzed based on the first risk analysis result.

[0212] In some optional implementations, the second risk analysis unit 703 is configured to:

[0213] taking each first known risk behavior among the plurality of first known risk behaviors as a first behavior to be compared, to obtain first behavior association information of the first behavior to be compared;

[0214] Obtaining second behavior association information of an unknown behavior;

[0215] By comparing the correlation between the first behavior correlation information and the second behavior correlation information, a second risk analysis result for the unknown behavior is obtained.

[0216] In some optional implementations, the second risk analysis unit 703 is configured to:

[0217] By comparing the correlation between the first behavior correlation information and the second behavior correlation information, a preliminary analysis result for the unknown behavior is obtained;

[0218] When the initial analysis result indicates that the unknown behavior is a risky behavior, the initial analysis result is used as the second risk analysis result for the unknown behavior; or, when the initial analysis result indicates that the unknown behavior is a non-risky behavior, the large language model is used to obtain the second risk analysis result for the unknown behavior.

[0219] In some optional implementations, the second risk analysis unit 703 is configured to:

[0220] Using large language models, multiple second-known risk behaviors are identified;

[0221] taking each second known risk behavior among the plurality of second known risk behaviors as a second behavior to be compared, to obtain third behavior association information of the second behavior to be compared;

[0222] By comparing the correlation between the second behavior correlation information and the third behavior correlation information, a second risk analysis result for the unknown behavior is obtained.

[0223] In some optional implementations, the first risk analysis unit 702 is configured to:

[0224] Through the static feature comparison strategy, risk analysis is performed on multiple features to be analyzed, and the first-class analysis results for multiple features to be analyzed are obtained;

[0225] Through the dynamic behavior detection strategy, risk analysis is performed on multiple features to be analyzed, and the second type of analysis results for multiple features to be analyzed are obtained;

[0226] Based on the first type of analysis results and the second type of analysis results, a first risk analysis result for the plurality of features to be analyzed is obtained.

[0227] In some optional implementations, the multiple features to be analyzed include multiple code snippets to be analyzed; the first risk analysis unit 702 is configured to:

[0228] Each of the multiple code fragments to be analyzed is used as a target code fragment, and features of the target code fragment are compared with multiple known risk code fragments to obtain a single fragment analysis result for the target code fragment;

[0229] Based on the single fragment analysis results, an overall analysis result for the multiple code fragments to be analyzed is obtained as a first-type analysis result for the multiple features to be analyzed.

[0230] In some optional implementations, the multiple features to be analyzed include multiple behaviors to be analyzed; and the first risk analysis unit 702 is configured to:

[0231] Taking each of the multiple behaviors to be analyzed as a target behavior, and comparing the characteristics of the target behavior with the multiple first known risk behaviors, to obtain a single behavior analysis result for the target behavior;

[0232] Based on the single behavior analysis result, an overall analysis result for multiple behaviors to be analyzed is obtained as a second type of analysis result for multiple features to be analyzed.

[0233] In the embodiment of the present disclosure, the specific functions and examples of each unit in the program analysis device 700 can be found in the relevant descriptions of the corresponding steps in the aforementioned embodiment of the program analysis method applied to the second electronic device, and are not repeated here.

[0234] In the technical solutions disclosed herein, the acquisition, storage, and application of user personal information involved comply with the provisions of relevant laws and regulations and do not violate public order and good morals.

[0235] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.

[0236] Figure 8 A schematic block diagram of an example electronic device 800 that can be used to implement an embodiment of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as vehicle-mounted computing devices, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0237] like Figure 8 As shown, the electronic device 800 includes a computing unit 801, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 802 or a computer program loaded from a storage unit 808 into a random access memory (RAM) 803. In the RAM 803, various programs and data required for the operation of the electronic device 800 can also be stored. The computing unit 801, the ROM 802, and the RAM 803 are connected to each other via a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.

[0238] Multiple components in the electronic device 800 are connected to the I / O interface 805, including: an input unit 806, such as a keyboard, a mouse, etc.; an output unit 807, such as various types of renderers, speakers, etc.; a storage unit 808, such as a magnetic disk, an optical disk, etc.; and a communication unit 809, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 809 allows the electronic device 800 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0239] The computing unit 801 can be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the computing unit 801 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units that run machine learning model algorithms, digital signal processors (DSPs), and any appropriate processors, controllers, microcontrollers, etc. The computing unit 801 performs the various methods and processes described above, such as the program analysis method. For example, in some embodiments, the program analysis method can be implemented as a computer software program that is tangibly contained in a machine-readable medium, such as a storage unit 808. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 800 via the ROM 802 and / or the communication unit 809. When the computer program is loaded into the RAM 803 and executed by the computing unit 801, one or more steps in the program analysis method described above can be performed. Alternatively, in other embodiments, the computing unit 801 may be configured as a program analysis method in any other appropriate manner (eg, by means of firmware).

[0240] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system on chips (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0241] The program code for implementing the method of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device so that when the program code is executed by the processor or controller, the functions / operations specified in the flow chart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0242] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in conjunction with an instruction execution system, device or equipment. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a RAM, a ROM, an erasable programmable read-only memory (EPROM) or flash memory, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0243] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a rendering device (e.g., a cathode ray tube (CRT) renderer or a liquid crystal display (LCD) renderer) for rendering information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices are also used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0244] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.

[0245] A computer system may include a client and a server. The client and server are generally remote from each other and typically interact via a communication network. The client-server relationship arises through computer programs running on the respective computers and establishing a client-server relationship. The server may be a cloud server, a server in a distributed system, or a server integrated with a blockchain.

[0246] An embodiment of the present disclosure further provides a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to enable a computer to execute a program analysis method.

[0247] An embodiment of the present disclosure further provides a computer program product, including a computer program, which implements the program analysis method when executed by a processor.

[0248] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps recorded in this disclosure can be executed in parallel, sequentially or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and this document is not limited here. In addition, in this disclosure, relational terms such as "first", "second", "third", etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply that there is any such actual relationship or order between these entities or operations. In addition, "multiple" in this disclosure can be understood as at least two.

[0249] The above specific embodiments do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the principles of this disclosure shall be included within the scope of protection of this disclosure.

Claims

1. A program analysis method, comprising: Obtain multiple features to be analyzed of the target program; Performing risk analysis on the multiple features to be analyzed by using a static feature comparison strategy and / or a dynamic behavior detection strategy to obtain a first risk analysis result for the multiple features to be analyzed; taking each first known risk behavior among the plurality of first known risk behaviors as a first behavior to be compared, to obtain first behavior association information of the first behavior to be compared; Obtaining second behavior association information of an unknown behavior; wherein the unknown behavior is determined from the multiple features to be analyzed based on the first risk analysis result; Obtaining a primary analysis result for the unknown behavior by comparing the first behavior association information and the second behavior association information; In the case where the initial analysis result indicates that the unknown behavior is a risky behavior, the initial analysis result is used as a second risk analysis result for the unknown behavior; or, in the case where the initial analysis result indicates that the unknown behavior is a non-risky behavior, a large language model is used to determine multiple second known risk behaviors, and each of the multiple second known risk behaviors is used as a second behavior to be compared, so as to obtain third behavior association information of the second behavior to be compared, and then the second behavior association information and the third behavior association information are compared for correlation to obtain a second risk analysis result for the unknown behavior; Among them, the behavior association information includes external behavior association information and internal behavior patterns; the external behavior association information includes a preset number of external behaviors that are positionally associated with the current behavior subject, and the positional association relationship between the current behavior subject and the preset number of external behaviors; the internal behavior pattern includes the internal behavior actions of the current behavior subject.

2. The method according to claim 1, wherein The risk analysis is performed on the multiple features to be analyzed by using a static feature comparison strategy and / or a dynamic behavior detection strategy to obtain a first risk analysis result for the multiple features to be analyzed, including: Performing risk analysis on the multiple features to be analyzed using a static feature comparison strategy to obtain a first type of analysis result for the multiple features to be analyzed; Performing risk analysis on the multiple features to be analyzed using a dynamic behavior detection strategy to obtain a second type of analysis result for the multiple features to be analyzed; Based on the first type of analysis results and the second type of analysis results, a first risk analysis result for the multiple features to be analyzed is obtained.

3. The method according to claim 2, wherein: The multiple features to be analyzed include multiple code snippets to be analyzed; and the risk analysis is performed on the multiple features to be analyzed using a static feature comparison strategy to obtain a first type of analysis result for the multiple features to be analyzed, including: Taking each of the multiple code fragments to be analyzed as a target code fragment, and performing feature comparison on the target code fragment with multiple known risk code fragments, to obtain a single fragment analysis result for the target code fragment; Based on the single fragment analysis result, an overall analysis result for the multiple code fragments to be analyzed is obtained as a first type of analysis result for the multiple features to be analyzed.

4. The method according to claim 2, wherein: The multiple features to be analyzed include multiple behaviors to be analyzed; and the risk analysis is performed on the multiple features to be analyzed using the dynamic behavior detection strategy to obtain the second type of analysis results for the multiple features to be analyzed, including: Taking each of the plurality of behaviors to be analyzed as a target behavior, and performing feature comparisons on the target behavior with a plurality of first known risk behaviors, to obtain a single behavior analysis result for the target behavior; Based on the single behavior analysis result, an overall analysis result for the multiple behaviors to be analyzed is obtained as a second type of analysis result for the multiple features to be analyzed.

5. A program analysis method comprising: Based on the target program, multiple features to be analyzed are obtained; Sending the plurality of features to be analyzed to a service device; wherein the service device is configured to: Performing risk analysis on the multiple features to be analyzed by using a static feature comparison strategy and / or a dynamic behavior detection strategy to obtain a first risk analysis result for the multiple features to be analyzed; taking each first known risk behavior among the plurality of first known risk behaviors as a first behavior to be compared, to obtain first behavior association information of the first behavior to be compared; Obtaining second behavior association information of an unknown behavior; wherein the unknown behavior is determined from the multiple features to be analyzed based on the first risk analysis result; Obtaining a primary analysis result for the unknown behavior by comparing the first behavior association information and the second behavior association information; In the case where the initial analysis result indicates that the unknown behavior is a risky behavior, the initial analysis result is used as a second risk analysis result for the unknown behavior; or, in the case where the initial analysis result indicates that the unknown behavior is a non-risky behavior, a large language model is used to determine multiple second known risk behaviors, and each of the multiple second known risk behaviors is used as a second behavior to be compared, so as to obtain third behavior association information of the second behavior to be compared, and then the second behavior association information and the third behavior association information are compared for correlation to obtain a second risk analysis result for the unknown behavior; Among them, the behavior association information includes external behavior association information and internal behavior patterns; the external behavior association information includes a preset number of external behaviors that are positionally associated with the current behavior subject, and the positional association relationship between the current behavior subject and the preset number of external behaviors; the internal behavior pattern includes the internal behavior actions of the current behavior subject.

6. The method according to claim 5, wherein: Based on the target program, multiple features to be analyzed are obtained, including: Decompile the target program to obtain the code decompilation result; Cut the code decompilation results to obtain multiple code fragments to be analyzed; Based on the multiple code snippets to be analyzed, multiple features to be analyzed are obtained.

7. The method according to claim 5, wherein: Based on the target program, multiple features to be analyzed are obtained, including: Perform dynamic behavior detection on the target program to obtain multiple behaviors to be analyzed; Based on the multiple behaviors to be analyzed, multiple features to be analyzed are obtained.

8. The method according to claim 7, wherein: The target program is dynamically tested for behavior, and multiple behaviors to be analyzed are obtained, including: Detection and adversarial technology is used to perform dynamic behavior detection on the target program and obtain multiple behaviors to be analyzed.

9. A program analysis device comprising: A first feature acquisition unit is used to acquire a plurality of features to be analyzed of the target program; A first risk analysis unit is configured to perform risk analysis on the plurality of features to be analyzed by using a static feature comparison strategy and / or a dynamic behavior detection strategy to obtain a first risk analysis result for the plurality of features to be analyzed; The second risk analysis unit is used to: taking each first known risk behavior among the plurality of first known risk behaviors as a first behavior to be compared, to obtain first behavior association information of the first behavior to be compared; Obtaining second behavior association information of an unknown behavior; wherein the unknown behavior is determined from the multiple features to be analyzed based on the first risk analysis result; Obtaining a primary analysis result for the unknown behavior by comparing the first behavior association information and the second behavior association information; In the case where the initial analysis result indicates that the unknown behavior is a risky behavior, the initial analysis result is used as a second risk analysis result for the unknown behavior; or, in the case where the initial analysis result indicates that the unknown behavior is a non-risky behavior, a large language model is used to determine multiple second known risk behaviors, and each of the multiple second known risk behaviors is used as a second behavior to be compared, so as to obtain third behavior association information of the second behavior to be compared, and then the second behavior association information and the third behavior association information are compared for correlation to obtain a second risk analysis result for the unknown behavior; Among them, the behavior association information includes external behavior association information and internal behavior patterns; the external behavior association information includes a preset number of external behaviors that are positionally associated with the current behavior subject, and the positional association relationship between the current behavior subject and the preset number of external behaviors; the internal behavior pattern includes the internal behavior actions of the current behavior subject.

10. The device according to claim 9, wherein The first risk analysis unit is used to: Performing risk analysis on the multiple features to be analyzed using a static feature comparison strategy to obtain a first type of analysis result for the multiple features to be analyzed; Performing risk analysis on the multiple features to be analyzed using a dynamic behavior detection strategy to obtain a second type of analysis result for the multiple features to be analyzed; Based on the first type of analysis results and the second type of analysis results, a first risk analysis result for the multiple features to be analyzed is obtained.

11. The device according to claim 10, wherein The multiple features to be analyzed include multiple code snippets to be analyzed; the first risk analysis unit is used to: Taking each of the multiple code fragments to be analyzed as a target code fragment, and performing feature comparison on the target code fragment with multiple known risk code fragments, to obtain a single fragment analysis result for the target code fragment; Based on the single fragment analysis result, an overall analysis result for the multiple code fragments to be analyzed is obtained as a first type of analysis result for the multiple features to be analyzed.

12. The device according to claim 10, wherein The multiple features to be analyzed include multiple behaviors to be analyzed; the first risk analysis unit is used to: Taking each of the plurality of behaviors to be analyzed as a target behavior, and performing feature comparisons on the target behavior with a plurality of first known risk behaviors, to obtain a single behavior analysis result for the target behavior; Based on the single behavior analysis result, an overall analysis result for the multiple behaviors to be analyzed is obtained as a second type of analysis result for the multiple features to be analyzed.

13. A program analysis device comprising: A second feature acquisition unit is used to obtain a plurality of features to be analyzed based on the target program; A feature sending unit is used to send the multiple features to be analyzed to a service device; wherein the service device is used to: Performing risk analysis on the multiple features to be analyzed by using a static feature comparison strategy and / or a dynamic behavior detection strategy to obtain a first risk analysis result for the multiple features to be analyzed; taking each first known risk behavior among the plurality of first known risk behaviors as a first behavior to be compared, to obtain first behavior association information of the first behavior to be compared; Obtaining second behavior association information of an unknown behavior; wherein the unknown behavior is determined from the multiple features to be analyzed based on the first risk analysis result; Obtaining a primary analysis result for the unknown behavior by comparing the first behavior association information and the second behavior association information; In the case where the initial analysis result indicates that the unknown behavior is a risky behavior, the initial analysis result is used as a second risk analysis result for the unknown behavior; or, in the case where the initial analysis result indicates that the unknown behavior is a non-risky behavior, a large language model is used to determine multiple second known risk behaviors, and each of the multiple second known risk behaviors is used as a second behavior to be compared, so as to obtain third behavior association information of the second behavior to be compared, and then the second behavior association information and the third behavior association information are compared for correlation to obtain a second risk analysis result for the unknown behavior; Among them, the behavior association information includes external behavior association information and internal behavior patterns; the external behavior association information includes a preset number of external behaviors that are positionally associated with the current behavior subject, and the positional association relationship between the current behavior subject and the preset number of external behaviors; the internal behavior pattern includes the internal behavior actions of the current behavior subject.

14. The device according to claim 13, wherein The second feature acquisition unit is used to: Decompile the target program to obtain the code decompilation result; Cut the code decompilation results to obtain multiple code fragments to be analyzed; Based on the multiple code snippets to be analyzed, multiple features to be analyzed are obtained.

15. The device according to claim 13, wherein The second feature acquisition unit is used to: Perform dynamic behavior detection on the target program to obtain multiple behaviors to be analyzed; Based on the multiple behaviors to be analyzed, multiple features to be analyzed are obtained.

16. The device according to claim 15, wherein The second feature acquisition unit is used to: Detection and adversarial technology is used to perform dynamic behavior detection on the target program and obtain multiple behaviors to be analyzed.

17. An electronic device comprising: at least one processor; a memory communicatively coupled to the at least one processor; The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 8.

18. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to enable the computer to execute the method according to any one of claims 1 to 8.

19. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Malicious application detection method and system

    CN106557695A

  • APP application malicious behavior detection method and device

    CN109214178A