Application detection method and device, electronic equipment and storage medium

By simulating user actions to generate an operational behavior simulation model, and combining dynamic and static analysis, the problem of incomplete detection of anomalies in application testing is solved, improving the accuracy and authenticity of detection and ensuring the security of user privacy data.

CN119740234BActive Publication Date: 2025-11-18CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411746375.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-29
Publication Date
2025-11-18
Estimated Expiration
2044-11-29

AI Technical Summary

Technical Problem

Existing technologies struggle to comprehensively detect anomalies in application detection, and the authenticity and accuracy of the detection results are low.

Method used

By simulating user behavior under different application operating states, an operational behavior simulation model is generated, mapped to the target application, application data of related behaviors are obtained, and dynamic and static analysis is performed to generate security detection results.

Benefits of technology

It enables comprehensive testing of applications, improving the accuracy and authenticity of testing and ensuring the security of user privacy data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119740234B_ABST
    Figure CN119740234B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a kind of detection method, device, electronic equipment and storage medium of application program, related to data security technical field, the method comprises: in response to running target application program on electronic equipment, determine the operation behavior simulation model for target application program, and according to operation behavior simulation model, simulate the simulation behavior of target application program under different application running state;Simulated behavior is mapped to target application program, in response to executing simulation behavior on target application program, determine the associated behavior corresponding to simulation behavior;Obtain the application data called by associated behavior;According to simulation behavior and the application data called by associated behavior, the security detection of target application program is carried out, generates the security detection result for target application program, to ensure the comprehensiveness, authenticity and accuracy of application program detection.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data security, in particular to a detection method of an application program, a detection device of an application program, an electronic device and a computer readable storage medium. BACKGROUND

[0002] APP(Application, application program) information security compliance detection is a process of evaluating and verifying the security and compliance of mobile application programs, which aims to find and correct privacy issues and compliance violations in the application program, etc., to ensure the protection of user data and the compliance of privacy.

[0003] Among them, for APP information security compliance detection, a combination of automated tools and manual review can be used, automated tools can scan the code and configuration files of the application program to find common security problems and privacy violations; manual review can identify some complex or specific security problems and compliance issues by in-depth inspection of the functions and processes of the application program.

[0004] However, in the process of detecting the APP, it is still difficult to detect all abnormal problems existing in the APP, and the detection result has the problems of low authenticity and accuracy. SUMMARY

[0005] The embodiments of the present application provide a detection method, device, electronic device and computer readable storage medium of an application program, to solve or partially solve the problems of difficult to detect all abnormal problems existing in the application program in the detection process of the application program, and low authenticity and accuracy of the detection result.

[0006] The embodiments of the present application disclose a detection method of an application program, comprising:

[0007] In response to running a target application program on an electronic device, determining an operation behavior simulation model for the target application program, and simulating a simulation behavior of the target application program under different application running states according to the operation behavior simulation model, the simulation behavior being an application behavior of the target application program in the application running state;

[0008] Mapping the simulation behavior to the target application program, in response to executing the simulation behavior on the target application program, determining an associated behavior corresponding to the simulation behavior, the associated behavior being an operation or event triggered by the target application program in response to the simulation behavior;

[0009] Obtaining application data called by the associated behavior;

[0010] According to the simulation behavior and the application data of the associated behavior call, the target application program is subjected to security detection, and a security detection result of the target application program is generated, which is used to represent whether the target application program has a security problem and / or an abnormal operation behavior.

[0011] The embodiment of the application discloses a detection device of an application program, comprising:

[0012] A behavior determination module is configured to determine an operation behavior simulation model for a target application program in response to running the target application program on an electronic device, and simulate a simulation behavior of the target application program in different application running states according to the operation behavior simulation model, wherein the simulation behavior is an application behavior of the target application program in the application running state.

[0013] A behavior mapping module is configured to map the simulation behavior to the target application program, and determine an associated behavior corresponding to the simulation behavior in response to executing the simulation behavior on the target application program, wherein the associated behavior is an operation or an event triggered by the target application program in response to the simulation behavior.

[0014] A data acquisition module is configured to acquire application data of the associated behavior call.

[0015] A detection module is configured to perform security detection on the target application program according to the simulation behavior and the application data of the associated behavior call, and generate a security detection result of the target application program, which is used to represent whether the target application program has a security problem and / or an abnormal operation behavior.

[0016] The embodiment of the application further discloses an electronic device comprising a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory complete communication with each other through the communication bus.

[0017] The memory is configured to store a computer program.

[0018] The processor is configured to execute the program stored on the memory, and implement the method as described in the embodiment of the application.

[0019] The embodiment of the application further discloses a computer readable storage medium having instructions stored thereon, which, when executed by one or more processors, cause the processors to execute the method as described in the embodiment of the application.

[0020] The embodiment of the application has the following advantages:

[0021] In the embodiment of the present application, in the process of detecting the security of the application program, the detection device can determine the operation behavior simulation model of the target application program by responding to the running of the target application program on the electronic device, simulate the simulation behavior of the target application program in different application running states according to the operation behavior simulation model, the simulation behavior is the application behavior of the target application program in the application running state, then map the simulation behavior to the target application program, determine the associated behavior corresponding to the simulation behavior in response to the execution of the simulation behavior on the target application program, and then obtain the application data called by the associated behavior, the associated behavior is the operation or event triggered by the target application program in response to the simulation behavior, and then detect the security of the target application program according to the simulation behavior and the application data called by the associated behavior, generate the security detection result of the target application program, the security detection result is used to represent whether the target application program has security problems and / or abnormal operation behaviors, so that the application program is detected through the simulation behavior and the application data called by the associated behavior, which can effectively detect the abnormal problems that may exist in the application program, and can comprehensively detect the application program from multiple detection dimensions to ensure the accuracy of the detection, and the detection through the simulation of the application behavior of the application program in the application running state can effectively ensure the authenticity of the detection. BRIEF DESCRIPTION OF DRAWINGS

[0022] Figure 1 is a step flow chart of an application program detection method provided in the embodiment of the present application;

[0023] Figure 2 is a structural block diagram of an application program detection device provided in the embodiment of the present application;

[0024] Figure 3 is a block diagram of an electronic device provided in the embodiment of the present application. DETAILED DESCRIPTION

[0025] In order to make the above-mentioned objects, features and advantages of the present application more apparent and easy to understand, the present application will be further described in detail below with reference to the drawings and specific embodiments.

[0026] As an example, detecting the compliance and security of the application program can effectively ensure the safety of user privacy data and reduce the risk of application program leaking user data. However, in the related art, in the process of detecting the compliance and security of the application program, it is still difficult to comprehensively detect the abnormal problems existing in the APP, and the detection result has the problems of low authenticity and accuracy.

[0027] To this end, in the present application, the compliance detection method based on behavior deep mining aims to simulate the actual use scenario of the user, including the behavior of the application in the foreground, background, exit and re-entry, switching of function modules and other special states, and through the comprehensive use of static and dynamic analysis and the formulation of rules in special states, the behavior compliance verification process of the mobile application program is further focused on the privacy protection of the application in various states to ensure that the application can maintain the behavior in compliance with the regulations in various situations and protect the privacy rights and interests of the user. Specifically, in the process of security detection of the application program, the detection device can determine an operation behavior simulation model for the target application program by responding to the running of the target application program on the electronic device, simulate the simulation behavior of the target application program in different application running states according to the operation behavior simulation model, the simulation behavior is the application behavior of the target application program in the application running state, then map the simulation behavior to the target application program, respond to the execution of the simulation behavior on the target application program, determine the associated behavior corresponding to the simulation behavior, then obtain the application data called by the associated behavior, the associated behavior is the operation or event triggered by the target application program in response to the simulation behavior, and then perform security detection on the target application program according to the simulation behavior and the application data called by the associated behavior, and generate a security detection result for the target application program. The security detection result is used to represent whether the target application program has a security problem and / or abnormal operation behavior, so that the application program is detected through the simulation behavior and the application data called by the associated behavior, which can not only effectively detect the abnormal problems that may exist in the application program, but also comprehensively detect the application program from multiple detection dimensions, ensuring the accuracy of the detection, and detecting the application behavior of the application program in the application running state, which can effectively ensure the authenticity of the detection.

[0028] Referring to Figure 1 , a step flowchart of a detection method of an application program provided in an embodiment of the present application is shown, which can specifically include the following steps:

[0029] Step 101, in response to the running of the target application program on the electronic device, an operation behavior simulation model for the target application program is determined, and the simulation behavior of the target application program in different application running states is simulated according to the operation behavior simulation model, the simulation behavior is the application behavior of the target application program in the application running state;

[0030] In the embodiments of the present application, the compliance and security of the application can be detected before the application is released, so as to ensure that the application can effectively ensure the security of the user's private data in the process of using the application. Among them, the installation file corresponding to the application to be detected can be obtained, and the application can be installed on the corresponding electronic device based on the installation file, then the application can be operated by simulating the relevant user operations of the user using the application, and whether the relevant application behaviors of the application in response to the user operations meet the preset detection conditions is monitored, so as to determine whether the application meets the compliance and security.

[0031] In a specific implementation, the electronic device can determine an operation behavior simulation model for the target application in response to running the target application on the electronic device, and simulate the simulation behavior of the target application in different application running states according to the operation behavior simulation model, the simulation behavior being the application behavior of the target application in the application running state, so as to simulate the relevant simulation behavior through the operation behavior model, so as to associate the simulation behavior with the application, and improve the authenticity and accuracy of the application detection.

[0032] In a feasible implementation, for the operation behavior simulation model, which can be used to simulate the foreground application behavior of the application running on the real device, the operation behavior simulation model can be trained through a corresponding model training manner. Specifically, the operation behavior data of the user in the target application can be obtained first, and a limited state set for the target application can be determined, the limited state set including a plurality of application function use states corresponding to the application and the corresponding user operations in each application function use state. Then, the operation behavior data is used to construct state transition information corresponding to the target application, the state transition information being used to represent the transition from one application function use state to another application function use state. Then, the operation execution probability information corresponding to the target application is constructed according to the operation behavior data of the user in different application function use states, the operation execution probability information being used to represent the probability of the user executing different user operations in each application function use state. Then, the use scenario corresponding to the target application is obtained, and then the use scenario, the state transition information and the operation execution probability information are used for model training to generate the operation behavior simulation model for the target application.

[0033] It should be noted that for the use scene, it can be a scene in which the user uses the application, such as a use scene corresponding to function ① of the user using the application, a use scene corresponding to function ② of the user using the application, a use scene of inputting user operation A under function ① of the application, and the like. Thus, by determining the use scene, the application function use state, and the user operation, the actual use state of the user when using the application can be accurately simulated, thereby improving the authenticity and rationality of the application detection.

[0034] Among them, for the state transition information, it can be a state transition matrix, which can have different application function use states and transition times corresponding to each application function use state. Specifically, the transition times of the user between different application function use states can be obtained, and then each application function use state and the corresponding transition times are used to construct the state transition information corresponding to the target application.

[0035] In an example, the finite state set can be determined by analyzing the application function and the interface structure, and each state represents a specific application state. Then define user operations, including operations that the user can perform in each state, such as clicking buttons, sliding screens, and inputting text (or other operations). For example, for a third-party camera application, the application function use state can be defined as follows:

[0036] Camera interface state: represents the state that the user is using the camera application;

[0037] Photo editing state: represents the state that the user is editing a photo;

[0038] Video recording state: represents the state that the user is recording a video;

[0039] Camera setting state: represents the state that the user is adjusting the camera settings.

[0040] For the above four states, the user can define the operations as follows:

[0041] Function level, automatic identification component; APP illegal and irregular, authorized before, foreground, etc.

[0042] In the camera interface state, the user can take photos, record videos, apply filters, and the like;

[0043] In the photo editing state, the user can perform operations such as cropping, rotating, adjusting brightness, and the like;

[0044] In the video recording state, the user can perform operations such as starting recording, pausing recording, stopping recording, and the like;

[0045] In the camera setting state, the user can perform operations such as adjusting exposure, focusing, switching cameras, and the like.

[0046] For the operation execution probability, which can also be an observation transition matrix, represents the probability of the user performing different user operations in each application function use state, can be composed of various application function use states, user operations, and operation times, and the like. Specifically, the operation execution probability information corresponding to the target application program can be constructed by obtaining the operation times of the user performing user operations in each application function use state, and then using the operation times of each user operation in each application function use state, each user operation, and each application function use state.

[0047] In an example, the observation probability matrix can be constructed by counting the number of times the user performs different operations in each state; the probability of performing different operations in each state is calculated, i.e., the number of times of a certain operation in a certain state divided by the total number of operations. For example, for a third-party camera application, operation data performed by the user in different states can be collected, such as: the frequency of the user taking photos in the camera interface state, the probability of the user saving photos in the photo editing state, the probability of the user stopping recording and returning to the camera interface in the video recording state, and the like. Based on these data, an observation probability matrix can be constructed, where each element represents the probability of the user performing a certain operation in a certain state. For example, the rows of the matrix represent the states of the application, the columns represent the user operations, and the values in the matrix represent the probability of the user performing a certain operation in a certain state.

[0048] Based on the above process, the application behavior in the foreground when the application program is running on a real device can be simulated. Then, in the process of detecting the target application program, the target use scenario and the target application function use state for the target application program can be determined first, and then the target use scenario and the target application function use state are input into the operation behavior simulation model for prediction to obtain the simulated behavior of the target application program in the target use scenario performing the target application function use state, so as to map the simulated behavior to the target application program to simulate the user's use process of the application program.

[0049] It should be noted that the operation behavior simulation model can be a model constructed based on the Viterbi algorithm. By using the Viterbi algorithm, the user's operation behavior can be predicted in a specific use scenario and application function use state, and the predicted user operation can be mapped to the application program to simulate the user's use process of the application program, so that the operation behavior simulation model can simulate the user's real selection, improve the authenticity of the simulation and the accuracy of the evaluation result.

[0050] In an example, a use scenario can be selected first, for example, a scenario simulating a user using a camera application to take a photo; then, various application function use states in the simulation process are determined, for example, a camera interface state, a photo taking state, a photo editing state, and the like. Next, an operation behavior simulation model (such as a hidden Markov model, etc.) that has been trained is used to predict the next operation of the user according to the current function use state and the observed user behavior sequence using a Viterbi algorithm. For example, in the camera interface state, it is predicted according to the model that the user can perform a photo taking operation. Then, according to the predicted user operation, it is mapped to the corresponding function or interface in the camera application; for example, if the model predicts that the user is about to take a photo, the camera application automatically opens the camera interface, ready for the user to take a photo. So that after the predicted user operation is performed, the simulated behavior can be verified to ensure that the behavior of the camera application in a specific state meets the compliance requirements. For example, it is verified whether the photo taking behavior will trigger a geolocation permission request and whether the geolocation information is obtained only when the user authorizes.

[0051] Through the above process, it can be evaluated whether the behavior of the camera application in a specific scenario and state meets the compliance requirements and whether the privacy and security of the user can be protected during the user operation.

[0052] Step 102, mapping the simulated behavior to the target application program, determining an associated behavior corresponding to the simulated behavior in response to performing the simulated behavior on the target application program, the associated behavior being an operation or event triggered when the target application program responds to the simulated behavior;

[0053] In an embodiment of the present application, after the operation behavior simulation model predicts the corresponding simulated behavior, the simulated behavior can be mapped to the target application program so that the target application program performs the corresponding simulated behavior. It can be understood that in the process of performing the model behavior, the electronic device can determine an associated behavior corresponding to the simulated behavior in response to performing the simulated behavior on the target application program, and the associated behavior can be an operation or event triggered when the target application program responds to the simulated behavior.

[0054] In a specific implementation, the simulated behavior can include application behaviors of the application program in special states such as foreground, background, exit and re-entry, switching of function modules, and the like, and the associated behavior can be behaviors triggered when the application program performs the corresponding application behaviors, such as network communication, file access, permission request, and the like, which are not limited by the present application.

[0055] Step 103, obtaining application data called by the associated behavior;

[0056] Wherein, for the associated behavior, the application program can call corresponding application data when triggering the associated behavior, such as calling source code, resource files and configuration files and other data corresponding to the application program to realize corresponding application behavior.

[0057] Step 104, according to the simulation behavior and the application data called by the associated behavior, the target application program is detected, and the security detection result of the target application program is generated, which is used to represent whether the target application program has security problems and / or abnormal operation behavior.

[0058] In the embodiment of the application, when the simulation behavior and the application data called by the associated behavior are determined, the application program can be detected from different dimensions, such as the simulation behavior can correspond to the detection of the dynamic process involved in the application program, and the application data can correspond to the detection of the static file involved in the application program, and the security detection result includes the dynamic analysis result corresponding to the simulation behavior and the static analysis result corresponding to the associated behavior, the electronic device can perform dynamic analysis on the target application program according to the simulation behavior, and generate the dynamic analysis result of the target application program, and perform static analysis on the target application program according to the application data called by the associated behavior, and generate the static analysis result of the target application program, thereby on the one hand, dynamic analysis of application program compliance is performed, and on the other hand, source code, resources and file structure corresponding to each simulation behavior and associated behavior are collected for static analysis, dynamic analysis and static analysis are effectively interacted, potential problems can be better judged, and the comprehensiveness of application program detection is ensured.

[0059] For the process of dynamic analysis, the security detection condition for the target application program can be determined first, the security detection condition is used to judge whether the target application program meets the preset condition when executing the simulation behavior, then the simulation behavior is matched with the security detection condition, and the security detection result of the target application program is generated based on the matching result.

[0060] Wherein, the application running state at least includes foreground running state, and the simulation behavior at least includes one of data access behavior, network communication behavior, permission request behavior, operation response behavior, privacy change behavior, message notification behavior, data input behavior and application switching behavior, then the electronic device can respond to one of the simulation behaviors of the target application program executing data access behavior, network communication behavior, permission request behavior, operation response behavior, privacy change behavior, message notification behavior, data input behavior and application switching behavior, monitor the behavior result corresponding to the simulation behavior of the target application program, and then match the behavior result with the security detection condition, and perform security detection on the target application program based on the matching result, and generate the security detection result of the target application program.

[0061] It should be noted that the security detection condition at least includes one of a data access permission condition, a network communication encryption condition, a permission applicability condition, a user operation visibility condition, a privacy setting respect condition, a notification compliance condition, an interaction data security condition, and a state saving and restoring condition; the data access permission condition is used to judge whether the target application accesses data according to preset permission limit information when performing a data access behavior in a foreground running state; the network communication encryption condition is used to judge whether the target application encrypts a data communication process when performing a network communication behavior in the foreground running state; the permission applicability condition is used to judge whether the target application only requests an application permission associated with the simulation behavior when performing a permission request behavior in the foreground running state; the user operation visibility condition is used to judge whether the target application updates an application interface of the target application in real time in response to the simulation behavior when performing an operation response behavior in the foreground running state; the privacy setting respect condition is used to judge whether the target application responds to a privacy setting change of a user in real time when performing a privacy change behavior in the foreground running state; the notification compliance condition is used to judge whether content of a notification message sent by the target application when performing a message notification behavior in the foreground running state has abnormal information; the interaction data security condition is used to judge whether the target application encrypts and stores and encrypts and transmits data when responding to a data input behavior in the foreground running state; and the state saving and restoring condition is used to judge whether the target application is in a normal saving state and a normal restoring state when performing an application switching behavior in the foreground running state.

[0062] In an example, the corresponding security detection condition and the detection mode corresponding to each security detection condition can be set before the application is detected, for example:

[0063] Data access permission condition:

[0064] For sensitive data (such as location, contact, etc.), the application needs to explicitly inform the user of the purpose of using the data in the foreground state, and obtain the explicit authorization of the user;

[0065] Detection mode: The data access permission condition is observed whether the application accesses data according to the permission limit in the foreground state by simulating different permission settings in the simulation environment.

[0066] Network communication encryption condition:

[0067] All network communications performed by the application in the foreground state must use a secure encryption protocol to prevent sensitive data from being maliciously intercepted or eavesdropped when transmitted in the foreground state;

[0068] Detection method: Intercept the application's network communication in a simulated environment and check if the communication is encrypted to verify if the application makes encrypted communication in the foreground state.

[0069] Permission applicability condition:

[0070] Applications in the foreground activity state can only request permissions related to the current function, unnecessary permission requests will reduce user trust;

[0071] Detection method: Simulate different permission requests in a simulated environment and observe if the application only requests permissions related to the current function.

[0072] User operation visibility condition:

[0073] The application in the foreground state responds to user operations, including button clicks, swipes, etc., should update the interface in real time, provide clear operation feedback; cannot intercept or tamper with user operations in the foreground state to maintain user operation visibility and expected behavior;

[0074] Detection method: Simulate user operations in a simulated environment, then observe if the application responds in real time and updates the interface.

[0075] Privacy settings respect condition:

[0076] The application in the foreground state should respond promptly to user privacy setting changes, such as permission switch operations, and follow user personal privacy preferences;

[0077] Detection method: Simulate privacy setting changes in a simulated environment, then observe if the application can respond promptly to user privacy setting changes.

[0078] Notification compliance condition:

[0079] When the application sends notifications in the foreground state, the notification content should be compliant and should not contain misleading or false information; and users should be able to easily control notification reception and display in the foreground state;

[0080] Detection method: Simulate application sending notifications in a simulated environment, then check if the notification content is compliant.

[0081] Interaction data security condition:

[0082] When the application processes sensitive data input by the user in the foreground state, it should ensure the secure storage and transmission of data to prevent data leakage;

[0083] Detection method: Simulate user input of sensitive data in a simulated environment, then observe how the application handles this data.

[0084] State saving and restoring condition:

[0085] The application should properly save the state of the user in the foreground state, so as to restore the previous operation state when the application is switched and returned;

[0086] Detection method: simulate application switching and returning in a simulated environment, and then observe whether the application can correctly save and restore the state.

[0087] In addition, for the process of static analysis, the application data at least includes source code, configuration file and resource file, and the electronic equipment can obtain a static analysis model for static analysis of the target application program, then input at least one of the source code, the configuration file and the resource file into the static analysis model for feature extraction, obtain data features corresponding to the application data, and the data features at least include one of code tags, function calls, variable definitions, annotations and code structures, then mark one of the code tags, function calls, variable definitions, annotations and code structures through the static analysis model, obtain analysis tags for the application data, and finally based on each analysis tag, the static analysis result of the target application program is formed, so that the corresponding simulation behavior is predicted through the operation behavior simulation model, and the corresponding associated behavior is determined based on the model behavior, then the associated behavior is mapped to the source code, resource and file structure of the application program, which can provide more comprehensive and accurate resource mapping, and better reflect the complex relationship between the application program behavior and the resource under the consideration of state transition, sequence relationship and uncertainty.

[0088] In an example, for the process of static analysis, the source code, configuration files, resource files, etc. of known applications can be collected (to ensure that the dataset contains diversified code samples), and data cleaning and formatting can be performed to facilitate model use; data features that can help the model distinguish different problem types are extracted from the source code (including code tokens, function calls, variable definitions, comments, code structure, etc.); for third-party camera applications, data features can include: code tokens (such as permission requests), function calls (such as camera start functions), variable definitions (such as storage path variables), comments (such as security vulnerability comments), code structure (such as permission check logic), etc. Then, a label indicating whether a specific problem (such as a vulnerability, an error, etc.) exists can be added to each code sample in the dataset; for third-party camera applications, problems can include: privacy issues (such as unauthorized access to geographic location), security vulnerabilities (such as buffer overflow vulnerabilities), functional defects (such as the inability to normally use the photo function), etc. Then, a support vector machine (SVM) algorithm is trained using the labeled training data; and the model is evaluated using test data that did not participate in the training, and the accuracy, recall rate, precision, etc. of the model are calculated, and it is determined whether the calculated result is greater than or equal to a preset threshold, if yes, the support vector machine model is used to perform static analysis on the application resources located, and if not, the model is optimized by adjusting hyperparameters or adding features, etc. so as to perform static analysis on the behavior-related resources through the constructed support vector machine model, which has advantages in accuracy, processing high-dimensional data, processing nonlinear relationships, generalization ability, false positive rate, and unbalanced data, etc., and can improve the effect and performance of static analysis.

[0089] Further, based on the dynamic analysis result and the static analysis result of the above process, the analysis result can also be classified, such as "fast screening high credibility dynamic malicious behavior" and "fast screening high credibility static malicious behavior", and for the detection result in special state, the corresponding report is made, and the privacy protection situation of the application in various states is recorded, so that the detection personnel can better view the abnormal problems involved in the application, and then facilitate the detection personnel to timely execute the corresponding processing strategy for the application, such as allowing the application to be released, or the application to be uninstalled, etc.

[0090] It should be noted that the embodiments of the present application include but are not limited to the above examples, and it can be understood that those skilled in the art can also set according to actual needs under the guidance of the idea of the embodiments of the present application, and the present application does not limit this.

[0091] In the embodiment of the present application, in the process of security detection on the application program, the detection device can determine an operation behavior simulation model for the target application program by responding to running the target application program on the electronic device, simulate the simulation behavior of the target application program in different application running states according to the operation behavior simulation model, the simulation behavior is the application behavior when the target application program is in the application running state, then map the simulation behavior to the target application program, determine the associated behavior corresponding to the simulation behavior in response to executing the simulation behavior on the target application program, the associated behavior is the operation or event triggered by the target application program in response to the simulation behavior, and then perform security detection on the target application program according to the simulation behavior and the application data called by the associated behavior, generate a security detection result for the target application program, and the security detection result is used to represent whether the target application program has a security problem and / or abnormal operation behavior, so that the application program is detected through the simulation behavior and the application data called by the associated behavior, which can not only effectively detect the abnormal problems that may exist in the application program, but also comprehensively detect the application program from multiple detection dimensions, ensuring the accuracy of the detection, and detecting the application behavior of the application program in the application running state can effectively ensure the authenticity of the detection.

[0092] It should be noted that, for the method embodiment, in order to simply describe, it is expressed as a series of action combinations, but those skilled in the art should know that the embodiments of the present application are not limited by the order of the described actions, because according to the embodiments of the present application, certain steps can be performed in other order or simultaneously. Secondly, those skilled in the art should know that the embodiments described in the specification all belong to preferred embodiments, and the actions involved are not necessarily necessary for the embodiments of the present application.

[0093] Referring to Figure 2 , a structure block diagram of an application program detection device provided in the embodiment of the present application is shown, which can specifically include the following modules:

[0094] The behavior determination module 201 is configured to determine an operation behavior simulation model for the target application program by responding to running the target application program on the electronic device, and simulate the simulation behavior of the target application program in different application running states according to the operation behavior simulation model, the simulation behavior is the application behavior when the target application program is in the application running state;

[0095] The behavior mapping module 202 is configured to map the simulation behavior to the target application program, determine the associated behavior corresponding to the simulation behavior in response to executing the simulation behavior on the target application program, and the associated behavior is the operation or event triggered by the target application program in response to the simulation behavior.

[0096] a data acquisition module 203, configured to acquire application data of the associated behavior call;

[0097] a detection module 204, configured to perform security detection on the target application program according to the simulation behavior and the application data of the associated behavior call, and generate a security detection result for the target application program, the security detection result being used to represent whether the target application program has a security problem and / or an abnormal operation behavior.

[0098] In some possible implementation manners, the security detection result includes a dynamic analysis result corresponding to the simulation behavior and a static analysis result corresponding to the associated behavior, and the detection module 204 is specifically configured to:

[0099] perform dynamic analysis on the target application program according to the simulation behavior, and generate a dynamic analysis result for the target application program;

[0100] perform static analysis on the target application program according to the application data of the associated behavior call, and generate a static analysis result for the target application program.

[0101] In some possible implementation manners, the detection module 204 is specifically configured to:

[0102] determine a security detection condition for the target application program, the security detection condition being used to judge whether the target application program meets a preset condition when performing the simulation behavior;

[0103] match the simulation behavior with the security detection condition, and perform security detection on the target application program based on a matching result, and generate a security detection result for the target application program.

[0104] In some possible implementation manners, the application running state at least includes a foreground running state, the simulation behavior at least includes one of a data access behavior, a network communication behavior, a permission request behavior, an operation response behavior, a privacy change behavior, a message notification behavior, a data input behavior and an application switching behavior, and the detection module 204 is specifically configured to:

[0105] monitor a behavior result corresponding to the simulation behavior of the target application program in response to the target application program performing one of the simulation behaviors of the data access behavior, the network communication behavior, the permission request behavior, the operation response behavior, the privacy change behavior, the message notification behavior, the data input behavior and the application switching behavior;

[0106] The behavior result is matched with the security detection condition, and the target application is detected based on a matching result to generate a security detection result for the target application.

[0107] In some possible implementation manners, the security detection condition comprises at least one of a data access permission condition, a network communication encryption condition, a permission applicability condition, a user operation visibility condition, a privacy setting respect condition, a notification compliance condition, an interaction data security condition, and a state saving and restoring condition.

[0108] The data access permission condition is used to determine whether the target application accesses data according to preset permission limit information when the target application performs the data access behavior in the foreground running state.

[0109] The network communication encryption condition is used to determine whether the target application encrypts a data communication process when the target application performs the network communication behavior in the foreground running state.

[0110] The permission applicability condition is used to determine whether the target application requests only an application permission associated with the simulation behavior when the target application performs the permission request behavior in the foreground running state.

[0111] The user operation visibility condition is used to determine whether the target application updates an application interface of the target application in real time in response to the simulation behavior when the target application performs the operation response behavior in the foreground running state.

[0112] The privacy setting respect condition is used to determine whether the target application responds to a privacy setting change of a user in real time when the target application performs the privacy change behavior in the foreground running state.

[0113] The notification compliance condition is used to determine whether content of a notification message sent by the target application in the foreground running state has abnormal information when the target application performs the message notification behavior.

[0114] The interaction data security condition is used to determine whether the target application encrypts and stores data and encrypts and transmits data in real time when the target application responds to the data input behavior in the foreground running state.

[0115] The state saving and restoring condition is used to determine whether the target application is in a normal saving state and a normal restoring state when the target application performs the application switching behavior in the foreground running state.

[0116] In some possible implementation manners, the application data at least includes source code, configuration files and resource files, and the detection module 204 is specifically configured to: acquire a static analysis model used for static analysis of the target application program;

[0117] At least one of the source code, the configuration files and the resource files is input into the static analysis model for feature extraction, to obtain data features corresponding to the application data, and the data features at least include one of code tags, function calls, variable definitions, annotations and code structures;

[0118] The static analysis model is used to mark one of the code tags, the function calls, the variable definitions, the annotations and the code structures, to obtain analysis labels for the application data;

[0119] The analysis labels are used to form a static analysis result of the target application program.

[0120] In some possible implementation manners, the behavior determination module 201 is specifically configured to:

[0121] Acquire operation behavior data of a user in the target application program, and determine a finite state set for the target application program, wherein the finite state set includes a plurality of application function use states corresponding to the application program and user operations corresponding to each application function use state;

[0122] The operation behavior data is used to construct state transition information corresponding to the target application program, and the state transition information is used to represent transition from one application function use state to another application function use state;

[0123] According to the operation behavior data of the user in different application function use states, operation execution probability information corresponding to the target application program is constructed, and the operation execution probability information is used to represent probabilities of user operations in each application function use state;

[0124] Acquire a use scenario corresponding to the target application program;

[0125] According to the use scenario, the state transition information and the operation execution probability information, a model is trained to generate an operation behavior simulation model for the target application program.

[0126] In some possible implementation manners, the behavior determination module 201 is specifically configured to:

[0127] Acquire a transition frequency between different application function use states of the user;

[0128] The state transition information corresponding to the target application program is constructed by using each application function use state and corresponding transition times.

[0129] In some possible implementation manners, the behavior determination module 201 is specifically configured to:

[0130] The operation times of the user operations performed by the user in each application function use state are obtained.

[0131] The operation execution probability information corresponding to the target application program is constructed by using the operation times of each user operation in each application function use state, each user operation and each application function use state.

[0132] In some possible implementation manners, the behavior determination module 201 is specifically configured to:

[0133] A target use scenario and a target application function use state for the target application program are determined.

[0134] The target use scenario and the target application function use state are input into the operation behavior simulation model to perform prediction, to obtain a simulated behavior of the target application program in the target use scenario and performing the target application function use state.

[0135] For the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the related parts refer to the part of the method embodiment.

[0136] In addition, the embodiment of the application further provides an electronic device, which comprises a processor, a memory, and a computer program stored in the memory and executable on the processor. The computer program is executed by the processor to implement each process of the method embodiment of the application program detection method and achieve the same technical effects. To avoid repetition, no further description is given here.

[0137] The embodiment of the application further provides a computer readable storage medium, which stores a computer program. The computer program is executed by a processor to implement each process of the method embodiment of the application program detection method and achieve the same technical effects. To avoid repetition, no further description is given here. The computer readable storage medium includes a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0138] Figure 3 A hardware structure schematic diagram of an electronic device for implementing various embodiments of the application.

[0139] The electronic device 300 includes, but is not limited to, a radio frequency unit 301, a network module 302, an audio output unit 303, an input unit 304, a sensor 305, a display unit 306, a user input unit 307, an interface unit 308, a memory 309, a processor 310, and a power supply 311, etc. Those skilled in the art can understand that the electronic device structure involved in the embodiments of the present application does not constitute a limitation on the electronic device, and the electronic device can include more or less components than the illustration, or combine certain components, or different component arrangements. In the embodiments of the present application, the electronic device includes, but is not limited to, a mobile phone, a tablet computer, a notebook computer, a palm computer, a vehicle terminal, a wearable device, and a pedometer, etc.

[0140] It should be understood that in the embodiments of the present application, the radio frequency unit 301 can be used for receiving and sending signals in the process of information or call, specifically, receiving downlink data from the base station for the processor 310 to process, and sending uplink data to the base station. Generally, the radio frequency unit 301 includes, but is not limited to, an antenna, at least one amplifier, a transceiver, a coupler, a low noise amplifier, a duplexer, etc. In addition, the radio frequency unit 301 can also communicate with the network and other devices through a wireless communication system.

[0141] The electronic device provides wireless broadband Internet access for users through the network module 302, such as helping users to send and receive emails, browse web pages, and access streaming media, etc.

[0142] The audio output unit 303 can convert audio data received by the radio frequency unit 301 or the network module 302 or stored in the memory 309 into an audio signal and output as a sound. Moreover, the audio output unit 303 can also provide audio output related to a specific function performed by the electronic device 300 (for example, a call signal receiving sound, a message receiving sound, etc.). The audio output unit 303 includes a speaker, a buzzer, and a receiver, etc.

[0143] The input unit 304 is configured to receive audio or video signals. The input unit 304 can include a graphics processor (GPU) 3041 and a microphone 3042. The graphics processor 3041 processes image data of a still picture or a video obtained by an image capture device (e.g., a camera) in a video capture mode or an image capture mode. Processed image frames can be displayed on the display unit 306. Processed image frames can be stored in the memory 309 (or other storage medium) or transmitted via the radio frequency unit 301 or the network module 302. The microphone 3042 can receive sound and is capable of processing such sound as audio data. Processed audio data can be converted into a format that can be transmitted to a mobile communication base station via the radio frequency unit 301 in a telephone call mode.

[0144] The electronic device 300 further includes at least one sensor 305, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor includes an ambient light sensor and a proximity sensor, wherein the ambient light sensor can adjust the brightness of the display panel 3061 according to the brightness of ambient light, and the proximity sensor can turn off the display panel 3061 and / or the backlight when the electronic device 300 is moved to the ear. As one of the motion sensors, the accelerometer sensor can detect the magnitude of acceleration in each direction (generally three axes), and when at rest, can detect the magnitude and direction of gravity, and can be used to identify the electronic device posture (such as screen switching, related games, magnetometer posture calibration), vibration recognition related functions (such as pedometer, knock), and the like. The sensor 305 can also include a fingerprint sensor, a pressure sensor, an iris sensor, a molecular sensor, a gyroscope, a barometer, a hygrometer, a thermometer, an infrared sensor, and the like, which will not be described here.

[0145] The display unit 306 is configured to display information input by a user or information provided to the user. The display unit 306 can include a display panel 3061, which can be configured in the form of a liquid crystal display (LCD), an organic light-emitting diode (OLED), or the like.

[0146] The user input unit 307 can be used to receive inputted numerical or character information, and to generate key signal inputs related to user settings of the electronic device and control of functions. Specifically, the user input unit 307 includes a touch panel 3071 and other input devices 3072. The touch panel 3071, also called a touch screen, can collect touch operations of a user thereon or adjacent thereto (such as operations of a user using a finger, a stylus, or any suitable object or accessory on or adjacent to the touch panel 3071). The touch panel 3071 can include two parts, a touch detection device and a touch controller. The touch detection device detects a user's touch position and detects a signal resulting from a touch operation, and transmits the signal to the touch controller; the touch controller receives touch information from the touch detection device, and converts it into touch coordinates, and sends it to the processor 310, and receives commands from the processor 310 and executes them. In addition, the touch panel 3071 can be implemented in various types such as a resistive type, a capacitive type, an infrared type, and a surface acoustic wave type. In addition to the touch panel 3071, the user input unit 307 can also include other input devices 3072. Specifically, the other input devices 3072 can include, but are not limited to, a physical keyboard, function keys (such as volume control buttons, on / off buttons, etc.), trackballs, mice, joysticks, and the like, which will not be described here.

[0147] Further, the touch panel 3071 can be overlaid on the display panel 3061, and when the touch panel 3071 detects a touch operation thereon or adjacent thereto, it transmits to the processor 310 to determine the type of touch event, and then the processor 310 provides corresponding visual output on the display panel 3061 according to the type of touch event. It can be understood that in one embodiment, the touch panel 3071 and the display panel 3061 are implemented as two independent components to realize the input and output functions of the electronic device, but in some embodiments, the touch panel 3071 and the display panel 3061 can be integrated to realize the input and output functions of the electronic device, which is not limited here.

[0148] The interface unit 308 is an interface for connecting external devices to the electronic device 300. For example, the external devices can include a wired or wireless headset port, an external power supply (or battery charger) port, a wired or wireless data port, a memory card port, a port for connecting a device having an identification module, an audio input / output (I / O) port, a video I / O port, an earphone port, and the like. The interface unit 308 can be used to receive input (e.g., data information, power, etc.) from external devices and transmit the received input to one or more elements within the electronic device 300, or can be used to transmit data between the electronic device 300 and external devices.

[0149] The memory 309 can be used to store software programs and various data. The memory 309 can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, application programs required by at least one function (such as a sound playing function, an image playing function, etc.), and the like; and the data storage area can store data created according to the use of the mobile phone (such as audio data, a phone book, etc.), and the like. In addition, the memory 309 can include a high-speed random access memory, and can also include a nonvolatile memory, for example, at least one magnetic disk storage device, a flash memory device, or other volatile solid-state memory device.

[0150] The processor 310 is the control center of the electronic device, connects all parts of the electronic device through various interfaces and lines, executes various functions of the electronic device and processes data by running or executing software programs and / or modules stored in the memory 309 and calling data stored in the memory 309, and thus monitors the whole electronic device. The processor 310 can include one or more processing units; preferably, the processor 310 can integrate an application processor and a modem processor, wherein the application processor mainly processes an operating system, a user interface, and application programs, and the like, and the modem processor mainly processes wireless communication. It can be understood that the above-mentioned modem processor can also not be integrated into the processor 310.

[0151] The electronic device 300 can also include a power supply 311 (such as a battery) for supplying power to various components; preferably, the power supply 311 can be logically connected to the processor 310 through a power management system, so as to realize the functions of managing charging, discharging, and power consumption management, and the like through the power management system.

[0152] In addition, the electronic device 300 includes some functional modules that are not shown and will not be described here.

[0153] It should be noted that in this document, the term "comprising" or "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article, or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such a process, method, article, or device. Without more limitations, the element defined by the statement "including a" does not exclude the presence of additional identical elements in the process, method, article, or device including the element.

[0154] Those skilled in the art can clearly understand that the above-mentioned embodiment method can be realized by means of software and necessary general hardware platform, of course, it can also be realized by hardware, but in many cases, the former is a better embodiment. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes a plurality of instructions for making a terminal (which can be a mobile phone, computer, server, air conditioner, or network device) execute the method described in each embodiment of the present application.

[0155] The embodiments of the present application are described above with reference to the accompanying drawings, but the present application is not limited to the above-mentioned specific embodiments, and the above-mentioned specific embodiments are only illustrative, not restrictive. Those skilled in the art can make many forms without departing from the purpose of the present application and the scope protected by the claims under the inspiration of the present application, which all belong to the protection of the present application.

[0156] Those skilled in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in the embodiments of the present application can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solutions. Those skilled in the art can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0157] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the above-mentioned system, device and unit can refer to the corresponding process in the foregoing method embodiments, which will not be repeated here.

[0158] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only illustrative, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed units can be indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0159] The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed on multiple network units. Part or all of the units can be selected to achieve the purpose of the embodiment of the present application according to actual needs.

[0160] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit.

[0161] The functions, if realized in the form of software functional units and sold or used as independent products, can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application or the part of the present application that essentially contributes to the prior art or the part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various storage media that can store program codes, such as a U disk, a mobile hard disk, a ROM, a RAM, a magnetic disk or an optical disk.

[0162] The above is only a specific embodiment of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for detecting an application, characterized in that, include: In response to running a target application on an electronic device, an operation behavior simulation model for the target application is determined, and the simulated behavior of the target application under different application running states is simulated according to the operation behavior simulation model, wherein the simulated behavior is the application behavior when the target application is in the application running state; The simulated behavior is mapped to the target application. In response to executing the simulated behavior on the target application, an associated behavior corresponding to the simulated behavior is determined. The associated behavior is an operation or event triggered by the target application in response to the simulated behavior. Obtain the application data invoked by the associated behavior; Based on the simulated behavior and the application data invoked by the associated behavior, a security detection is performed on the target application to generate a security detection result for the target application. The security detection result is used to characterize whether the target application has security problems and / or abnormal operation behavior. The step of determining the operational behavior simulation model for the target application includes: Acquire user operation behavior data in the target application and determine a finite set of states for the target application. The finite set of states includes several application function usage states corresponding to the application and user operations corresponding to each application function usage state. The state transition information corresponding to the target application is constructed using operational behavior data. The state transition information is used to characterize the transition from one application function usage state to another application function usage state. Based on the user's operational behavior data under different application function usage states, operation execution probability information corresponding to the target application is constructed. The operation execution probability information is used to characterize the probability that the user performs different user operations under each application function usage state. Obtain the usage scenario corresponding to the target application; The model is trained based on the usage scenario, the state transition information, and the operation execution probability information to generate an operation behavior simulation model for the target application.

2. The method according to claim 1, characterized in that, The security detection results include dynamic analysis results corresponding to the simulated behavior and static analysis results corresponding to the associated behavior. The step of performing security detection on the target application based on the application data invoked by the simulated behavior and the associated behavior, and generating security detection results for the target application, includes: The target application is dynamically analyzed based on the simulated behavior to generate dynamic analysis results for the target application. Static analysis is performed on the target application based on the application data invoked by the associated behavior, generating static analysis results for the target application.

3. The method according to claim 2, characterized in that, The step of dynamically analyzing the target application based on the simulated behavior and generating dynamic analysis results for the target application includes: Determine the security detection conditions for the target application, which are used to determine whether the target application meets preset conditions when performing the simulated behavior; The simulated behavior is matched with the security detection conditions, and the target application is subjected to security detection based on the matching results to generate security detection results for the target application.

4. The method according to claim 3, characterized in that, The application running state includes at least a foreground running state, and the simulated behavior includes at least one of the following: data access behavior, network communication behavior, permission request behavior, operation response behavior, privacy change behavior, message notification behavior, data input behavior, and application switching behavior. The process of matching the simulated behavior with the security detection conditions, performing security detection on the target application based on the matching results, and generating security detection results for the target application includes: In response to the target application performing one of the following simulated behaviors: data access behavior, network communication behavior, permission request behavior, operation response behavior, privacy change behavior, message notification behavior, data input behavior, and application switching behavior, the corresponding behavioral results when the target application performs the simulated behavior are monitored. The behavioral result is matched with the security detection conditions, and the target application is subjected to security detection based on the matching result to generate a security detection result for the target application.

5. The method according to claim 4, characterized in that, The security detection conditions include at least one of the following: data access permission conditions, network communication encryption conditions, permission applicability conditions, user operation visibility conditions, privacy setting respect conditions, notification compliance conditions, interactive data security conditions, and state saving and recovery conditions; wherein... The data access permission conditions are used to determine whether the target application accesses data in accordance with preset permission restriction information when performing the data access behavior in the foreground running state; The network communication encryption condition is used to determine whether the target application encrypts the data communication process when performing the network communication behavior in the foreground running state; The permission applicability condition is used to determine whether the target application, when executing the permission request behavior in the foreground running state, only requests the application permissions associated with the simulated behavior; The user operation visibility condition is used to determine whether the target application updates the application interface of the target application in real time when the target application performs the operation response behavior in the foreground running state; The privacy settings respect condition is used to determine whether the target application responds to the user's privacy settings changes in real time when the privacy change behavior is performed in the foreground running state; The notification compliance condition is used to determine whether there is any abnormal information in the content of the notification message sent when the target application performs the message notification behavior in the foreground running state; The interactive data security condition is used to determine whether the target application performs encrypted storage and encrypted transmission of data when responding to the data input behavior in the foreground running state. The state saving and restoration conditions are used to determine whether the target application is in a normal saving state and a normal restoration state when the target application performs the application switching behavior in the foreground running state.

6. The method according to claim 2, characterized in that, The application data includes at least source code, configuration files, and resource files. The static analysis of the target application based on the application data invoked according to the associated behavior, generating static analysis results for the target application, includes: Obtain a static analysis model for static analysis of the target application; At least one of the source code, the configuration file, and the resource file is input into the static analysis model for feature extraction to obtain data features corresponding to the application data. The data features include at least one of code tags, function calls, variable definitions, comments, and code structure. The static analysis model is used to tag one of the following: code markers, function calls, variable definitions, comments, and code structures, to obtain analysis tags for the application data. The static analysis results of the target application are composed of each of the aforementioned analysis tags.

7. The method according to claim 1, characterized in that, The step of constructing state transition information corresponding to the target application using operational behavior data includes: Obtain the number of times the user transitions between different application function usage states; By using the usage status of each application function and the corresponding number of transitions, state transition information corresponding to the target application is constructed.

8. The method according to claim 1 or 7, characterized in that, The step of constructing operation execution probability information corresponding to the target application based on the user's operation behavior data under different application function usage states includes: The number of times the user performs user operations in each of the application function usage states is obtained; By using the number of operations of each user operation under each application function usage state, each user operation, and the usage state of each application function, operation execution probability information corresponding to the target application is constructed.

9. The method according to claim 1 or 7, characterized in that, The step of simulating the target application's behavior under different application running states based on the operational behavior simulation model includes: Determine the target use cases and the usage status of the target application's functions; The target usage scenario and the target application function usage state are input into the operation behavior simulation model for simulation and prediction, thereby obtaining the simulated behavior of the target application in the target usage scenario corresponding to the target application function usage state.

10. A detection device for an application, characterized in that, include: A behavior determination module is configured to, in response to running a target application on an electronic device, determine an operation behavior simulation model for the target application, and simulate the simulated behavior of the target application under different application running states according to the operation behavior simulation model, wherein the simulated behavior is the application behavior when the target application is in the application running state; A behavior mapping module is used to map the simulated behavior to the target application, and in response to executing the simulated behavior on the target application, to determine the associated behavior corresponding to the simulated behavior, wherein the associated behavior is an operation or event triggered by the target application in response to the simulated behavior; The data acquisition module is used to acquire the application data invoked by the associated behavior; The detection module is used to perform security detection on the target application based on the simulated behavior and the application data called by the associated behavior, and generate a security detection result for the target application. The security detection result is used to characterize whether the target application has security problems and / or abnormal operation behavior. Specifically, the behavior determination module is used for: Acquire user operation behavior data in the target application and determine a finite set of states for the target application. The finite set of states includes several application function usage states corresponding to the application and user operations corresponding to each application function usage state. The state transition information corresponding to the target application is constructed using operational behavior data. The state transition information is used to characterize the transition from one application function usage state to another application function usage state. Based on the user's operational behavior data under different application function usage states, operation execution probability information corresponding to the target application is constructed. The operation execution probability information is used to characterize the probability that the user performs different user operations under each application function usage state. Obtain the usage scenario corresponding to the target application; The model is trained based on the usage scenario, the state transition information, and the operation execution probability information to generate an operation behavior simulation model for the target application.

11. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus; The memory is used to store computer programs; When the processor executes a program stored in the memory, it implements the method as described in any one of claims 1-9.

12. A computer-readable storage medium having instructions stored thereon that, when executed by one or more processors, cause the processors to perform the method as described in any one of claims 1-9.

Citation Information

Patent Citations

  • Autonomous vehicle planning

    CN112888612A

  • Financial expenditure behavior anomaly prediction method based on distributed model training

    CN115880086A