Method, device and equipment for detecting application program
By obtaining and correcting terminal operating parameters and temperature information, the error problem caused by temperature fluctuations in application detection is solved, and more accurate detection results are achieved.
Patent Information
- Application Number
- CN202510085097.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-20
- Publication Date
- 2025-05-13
AI Technical Summary
During application detection, due to the temperature fluctuation of the terminal hardware module affects the stability of the terminal operating parameters, resulting in errors in the detection results.
By obtaining the terminal operation parameter information and temperature information of the application in the running state, if the temperature exceeds the preset threshold, the operation parameter information is corrected to reduce the impact of temperature changes, thereby generating more accurate detection results.
Improves the accuracy of application detection, reduces detection errors, and ensures that accurate terminal operation parameter information and detection results can still be provided in the case of temperature fluctuations.
Smart Images

Figure CN119989348A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer security, and in particular to a method, a device and equipment for application program detection. Background Art
[0002] For applications, potential malicious behaviors can be identified by analyzing the application's behavioral characteristics, code structure, and the interaction pattern between the application and the operating system to ensure the security of user devices.
[0003] However, in a specific application scenario, the temperature fluctuation of the hardware module of the terminal running the application may affect the stability of the acquired terminal operation parameters, thereby causing errors in the detection results. Summary of the invention
[0004] In view of this, the present invention provides a method, apparatus and device for application detection to solve the problem of high application detection error in the related art.
[0005] In a first aspect, the present invention provides a method for application detection, the method comprising: obtaining terminal operating parameter information when the application is in a running state, if the terminal operating parameter represented by the terminal operating parameter information exceeds a preset parameter threshold, recording the terminal operating parameter information and user operation; obtaining terminal operating temperature information when the application is in a running state, if the terminal operating temperature represented by the terminal operating temperature information exceeds a preset temperature threshold, correcting the terminal operating parameter information; generating an application detection result based on the terminal operating parameter information, the user operation and the terminal operating temperature information.
[0006] In an optional implementation, the method of obtaining terminal operating parameter information when the application is in a running state includes: determining a data acquisition protocol based on the hardware interface type of the terminal; and obtaining the terminal operating parameter information by multi-threading based on the data acquisition protocol; wherein the data acquisition protocol includes a data acquisition frequency and a data verification frequency.
[0007] In an optional embodiment, the data acquisition protocol is determined based on the hardware interface type of the terminal, including: determining the hardware interface type based on a hardware feature code library; loading a data acquisition driver corresponding to the hardware interface type based on the hardware interface type; if the hardware interface type is a preset hardware interface type and the data acquisition driver is a preset data acquisition driver, increasing the data verification frequency.
[0008] In an optional embodiment, the method also includes: storing and retrieving hardware feature codes based on a hash algorithm; updating the hardware feature code library based on one or more of the following methods: acquiring new hardware feature codes according to a preset period based on an automated script, and adding the new hardware feature codes to the hardware feature code library; deleting invalid hardware feature codes in the hardware feature code library; marking invalid hardware feature codes in the hardware feature code library; and updating the hardware feature code library offline.
[0009] In an optional embodiment, based on the data acquisition protocol, multi-threaded acquisition of the terminal operating parameter information includes: detecting the current available data transmission channels, evaluating the data delay and packet loss rate of each channel; determining a target data transmission channel, wherein the target data transmission channel is the data transmission channel with the smallest data delay among the available data transmission channels whose packet loss rate is lower than a preset packet loss threshold; based on the target data transmission channel, transmitting the terminal operating parameter information.
[0010] In an optional embodiment, the method further includes: in the process of transmitting the terminal operating parameter information, if the packet loss rate of the target data transmission channel is higher than or equal to the preset packet loss threshold, or the data delay of the target data transmission channel is greater than the maximum data delay threshold, re-determining a new target data transmission channel.
[0011] In an optional embodiment, the generating of the application detection result based on the terminal operating parameter information, the user operation and the terminal operating temperature information includes: converting the terminal operating parameter information, the user operation and the terminal operating temperature information into a preset data format; extracting numerical features and classification features from data in the preset data format; identifying abnormal patterns based on the numerical features and the classification features to obtain recognition results; and generating the application detection result based on the recognition result.
[0012] In an optional embodiment, if the terminal operating temperature represented by the terminal operating temperature information exceeds a preset temperature threshold, the terminal operating parameter information is corrected, including: when the terminal operating temperature represented by the terminal operating temperature information exceeds the preset temperature threshold, the terminal operating parameter information is obtained; and the terminal operating parameter information is weighted or smoothed and filtered to correct the terminal operating parameter information.
[0013] In a second aspect, the present invention provides a device for application detection, the device comprising:
[0014] The first acquisition module is used to obtain the terminal operation parameter information when the application is in the running state; if the terminal operation parameter represented by the terminal operation parameter information exceeds the preset parameter threshold, the terminal operation parameter information and the user operation are recorded; the second acquisition module is used to obtain the terminal operation temperature information when the application is in the running state; if the terminal operation temperature represented by the terminal operation temperature information exceeds the preset temperature threshold, the terminal operation parameter information is corrected; the detection module is used to generate an application detection result based on the terminal operation parameter information, the user operation and the terminal operation temperature information.
[0015] In a third aspect, the present invention provides a computer device, comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the method for application detection of the above-mentioned first aspect or any corresponding embodiment thereof by executing the computer instructions.
[0016] In a fourth aspect, the present invention provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to cause a computer to execute the method for application detection of the above-mentioned first aspect or any corresponding embodiment thereof.
[0017] In a fifth aspect, the present invention provides a computer program product, comprising computer instructions for causing a computer to execute the method for application detection according to the first aspect or any corresponding embodiment thereof.
[0018] By obtaining terminal operating parameter information, terminal operating temperature information and user operations, more complete and accurate application operating status information can be obtained; by presetting parameter thresholds, application anomalies can be discovered in a timely manner when an application anomaly occurs; when the terminal operating temperature exceeds the preset temperature threshold, the terminal operating parameter information is corrected to ensure that the impact of temperature changes is corrected in the case of temperature fluctuations, accurate terminal operating parameter information can be provided, the error of application detection can be reduced, and accurate application detection results can be provided. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the related technologies, the drawings required for use in the specific embodiments or the related technical descriptions will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0020] Figure 1 A schematic diagram showing a flow chart of a method for application program detection according to an embodiment of the present invention;
[0021] Figure 2 A schematic diagram showing the structure of a device for application program detection according to an embodiment of the present invention is shown;
[0022] Figure 3 It is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0023] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present invention.
[0024] In the related art, due to the physical limitations of sensors and hardware interfaces in mobile devices, efficient data collection and analysis become difficult.
[0025] According to an embodiment of the present invention, a method embodiment for application detection is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0026] In this embodiment, a method for application detection is provided, which can be used in a mobile terminal, such as a mobile phone, a tablet computer, or a notebook computer. Figure 1 A schematic diagram of a process for detecting an application program according to an embodiment of the present invention is shown. Figure 1 As shown, the process includes the following steps:
[0027] Step S101, obtaining terminal operation parameter information when the application is in operation, and if the terminal operation parameter represented by the terminal operation parameter information exceeds a preset parameter threshold, recording the terminal operation parameter information and the user operation.
[0028] In this step, the terminal operation parameter information is the hardware parameters of the terminal during operation obtained through various sensors integrated in the terminal, including but not limited to CPU usage, memory usage or network traffic, etc.
[0029] High-bandwidth transmission technology can be used to obtain terminal operation parameter information. The most suitable bandwidth value can be automatically selected according to the current network conditions, ranging from 2Mbps to 100Mbps. When abnormal traffic is detected, the speed can be reduced or increased in time to ensure the balance between data integrity and transmission speed. By dynamically adjusting the transmission bandwidth, changes in the network environment can be effectively responded to. In this way, not only the transmission rate is improved, but also a stable data flow can be maintained under high load, which can reduce data collection time.
[0030] By obtaining terminal operation parameter information, the problem of low data collection efficiency caused by the physical limitations of the terminal hardware interface can be solved.
[0031] Step S102, obtaining terminal operation temperature information when the application is in operation, and if the terminal operation temperature represented by the terminal operation temperature information exceeds a preset temperature threshold, correcting the terminal operation parameter information.
[0032] In this step, the data fluctuations caused by thermal effects during data collection are corrected to ensure that accurate data support can still be provided in an environment with temperature changes. At the same time, the hardware operating temperature of the terminal can be monitored in real time.
[0033] Step S103: Generate application program detection results based on the terminal operation parameter information, user operation and terminal operation temperature information.
[0034] In this step, the data flow is monitored while obtaining the terminal operating parameter information, user operation and terminal operating temperature information. The continuity of the data flow can be ensured by monitoring the error rate, delay and packet loss of data transmission. When any abnormality is detected, such as transmission error or packet loss, the data verification and repair mechanism will be activated immediately. Specifically, if the system detects that a certain segment of video data has obvious frame loss, it will re-request the lost data segment for retransmission and use the forward error correction algorithm to restore the damaged part, thereby ensuring the consistency and integrity of the data.
[0035] The method for application detection in this embodiment can obtain more complete and accurate application operation status information by acquiring terminal operation parameter information, terminal operation temperature information and user operations; by presetting parameter thresholds, application anomalies can be discovered in a timely manner and malicious applications can be identified when an application anomaly occurs; when the terminal operation temperature exceeds the preset temperature threshold, the terminal operation parameter information is corrected, which can ensure that the impact of temperature changes is corrected in the case of temperature fluctuations, and accurate terminal operation parameter information can be provided, thereby reducing the error of application detection and providing accurate application detection results.
[0036] In some optional implementations, obtaining terminal operating parameter information when the application is in a running state includes: determining a data acquisition protocol based on the hardware interface type of the terminal; and obtaining the terminal operating parameter information by multi-threading based on the data acquisition protocol; wherein the data acquisition protocol includes a data acquisition frequency and a data verification frequency.
[0037] In this embodiment, the data acquisition protocol can adjust the communication parameters according to the specific characteristics of the hardware, such as the CPU architecture, memory type or network interface speed, so as to minimize the delay and packet loss rate during the data transmission process and improve the overall performance. For example, on a smart device using an ARM processor and a WiFi wireless module, the data acquisition protocol will automatically match the corresponding data acquisition frequency, data verification frequency and data packet format to maximize the throughput.
[0038] It is also possible to automatically generate a data collection configuration file suitable for the terminal device based on the automatic identification technology of the hardware interface type. This step is intended to determine the type of hardware interface available on the mobile device, such as Bluetooth, Wi-Fi, or NFC, through the identification algorithm provided by the terminal device, and generate corresponding configuration files according to different interface characteristics. For example, in one embodiment, the detection application can automatically generate a configuration file including the interface type, version, and maximum data transmission rate by reading the hardware information of the device. This information is used in the subsequent data collection process.
[0039] Multithreading obtains terminal operating parameter information. It can start four independent working threads to simultaneously process four different types of sensor data: GPS positioning, camera image, gyroscope angle change, and microphone audio, thereby significantly reducing the overall processing time. The use of multithreading processing mechanism improves the parallel capability of data collection.
[0040] In this way, the data acquisition protocol is determined based on the hardware interface type of the terminal, which can optimize the communication efficiency between the sensor and the terminal device hardware interface and ensure efficient data transmission. Based on the data acquisition protocol, multi-threading obtains terminal operation parameter information. Multi-threading allows multiple sensor data to be processed simultaneously, avoiding data waiting time and processing delay in a single process.
[0041] In some optional implementations, the data acquisition protocol is determined based on the hardware interface type of the terminal, including: determining the hardware interface type based on a hardware feature code library; loading a data acquisition driver corresponding to the hardware interface type based on the hardware interface type; if the hardware interface type is a preset hardware interface type and the data acquisition driver is a preset data acquisition driver, increasing the data verification frequency.
[0042] In this embodiment, the hardware interface type of the current terminal device can be determined based on the hardware feature code library. Through the pre-built hardware feature code library, the specific interface type of the current device is compared with the various hardware interfaces of the current terminal device. The hardware feature code library contains standard codes and identifiers of various device interfaces, so that the device type can be accurately and efficiently identified and the misidentification rate can be reduced. For example, for a database containing one or more mobile phone hardware feature codes, when a terminal device is connected, the device hardware information can be read and compared with the database to confirm whether the device uses a USB 3.0 interface or a Bluetooth 4.0 interface, etc.
[0043] Based on the matched hardware interface type, the data acquisition driver corresponding to the matched hardware interface type can be loaded. Different hardware interfaces may support different communication protocols or data transmission methods. For example, if the hardware interface type identification result shows that the current device uses a Wi-Fi 6 interface, you can choose to load the latest driver that supports the Wi-Fi 6 standard to more effectively collect network traffic and other information for malware detection. This can improve the efficiency and reliability of data collection.
[0044] When the identified hardware interface type is the preset hardware interface type I1, the loaded data acquisition driver version corresponding to I1 is V1, and the current terminal device model is M1, the data verification frequency is increased by F1 times / second. Among them, parameter I1 indicates the specific type of hardware interface; V1 specifies the driver version number used to ensure that the driver has the latest security patch; M1 indicates the specific device model, and some models of devices may have specific security risks; F1 represents the data verification frequency, in times / second.
[0045] Specifically, if the detected device is a Samsung Galaxy S20, it uses a USB Type-C interface and has loaded a USB driver with version 4.2.0, and this model has been exposed to have a security vulnerability in the USB interface, in order to enhance security, the data verification frequency is increased to 10 times / second, and potential malicious behavior is detected and prevented in a timely manner by increasing the verification frequency. The data verification frequency setting here is based on the best practices derived from multiple experiments, in order to provide maximum security without affecting performance.
[0046] In this way, security measures can be strengthened for special situations where security vulnerabilities exist to prevent malicious applications from exploiting known security vulnerabilities.
[0047] In some optional implementations, the aforementioned method for application detection further includes: updating a hardware signature library during data collection.
[0048] As new hardware continues to emerge, the existing hardware signature database may have certain limitations. It can be updated in real time according to the new hardware features to maintain the advancement and adaptability of the system. Specifically, whenever a new device model or interface type is added, the signature codes of these new hardware are collected and added to the signature database to ensure that the same device can be quickly and accurately identified in the future. It can enhance device compatibility, continuously expand and optimize the hardware signature database, so that more devices and interfaces can be accurately identified and supported.
[0049] In some optional implementations, the aforementioned method for application detection further includes: preprocessing different hardware interfaces. Specific filtering techniques and anti-interference strategies can be used to ensure that the hardware interfaces do not interfere with each other when working at the same time. Specifically, when the Wi-Fi and Bluetooth interfaces of the terminal device are turned on at the same time, the data transmission rate may decrease. At this time, this interference can be reduced by applying frequency band separation technology and time domain scheduling strategies through preprocessing steps.
[0050] In this way, the signal interference problem that may occur between hardware interfaces can be reduced, and the accuracy and reliability of data acquisition can be improved.
[0051] In some optional implementations, the aforementioned method for application detection further includes: adjusting the acquisition frequency and accuracy based on dynamic configuration management. According to actual conditions and needs, this step will dynamically adjust the data acquisition frequency and accuracy of each hardware interface to ensure a balance between performance and energy consumption. For example, for applications with high real-time requirements, the acquisition frequency can be increased; and for applications that are sensitive to power consumption, the acquisition frequency can be appropriately reduced without affecting the detection effect. Specifically, a dynamic adjustment algorithm can be set to automatically adjust the acquisition frequency and accuracy according to the current system load and user behavior to adapt to different usage scenarios.
[0052] In some optional implementations, the aforementioned method for application detection further includes: if the hardware interface type is a preset second hardware interface type and the integrity of the collected data is less than a preset data threshold, enabling a backup interface.
[0053] In this embodiment, when the integrity of the collected data is less than the preset data threshold T1 based on the preset second hardware interface type H1, the backup interface is switched to perform data collection. The preset data threshold T1 can be set between 70% and 90%, and the specific value can be optimized and adjusted according to actual application requirements.
[0054] Specifically, if the main data collection interface in a terminal device is Wi-Fi, and it is found during detection that the integrity of the collected data is only 60%, it can automatically switch to the backup interface, such as the mobile data network, to continue collecting and ensure the integrity and continuity of data transmission. This setting can ensure that reliable detection results can be obtained in any situation.
[0055] In this way, data continuity and reliability can be guaranteed for possible data loss or interruption problems.
[0056] In some optional embodiments, the aforementioned method for application detection also includes: storing and retrieving hardware feature codes based on a hash algorithm; updating the hardware feature code library based on one or more of the following methods: obtaining new hardware feature codes according to a preset period based on an automated script, and adding the new hardware feature codes to the hardware feature code library; deleting invalid hardware feature codes in the hardware feature code library; marking invalid hardware feature codes in the hardware feature code library; and updating the hardware feature code library offline.
[0057] In this embodiment, the hardware feature code is stored and retrieved based on the hash algorithm, and the hardware information of the device can be stored by selecting and applying the hash function. The SHA-256 hash algorithm can be used to encode the unique hardware identifier (ID) of each terminal device, generate a hash value of a fixed length, and store it in the hardware feature code library. When the system needs to verify the identity of a terminal device, the hash value of the terminal device is calculated by the same hash algorithm and compared with the record in the library, thereby achieving fast and accurate identity authentication.
[0058] In this way, the feature code can be quickly retrieved in a short time, the speed and efficiency of data processing can be improved, and high performance can still be maintained when processing large amounts of data.
[0059] The latest hardware signature codes can be obtained from trusted sources regularly through automated scripts and added to the existing library. At the same time, invalid or outdated entries in the library need to be deleted or marked. Specifically, in the case of each system update, the latest version of the hardware signature code database file can be automatically downloaded and installed to ensure that the signature code library on the device is always up to date, ensuring the timeliness and accuracy of the data.
[0060] The hardware signature library can also be updated offline. Specifically, the terminal device user can download the update package in advance in a network environment and save it on an SD card or other external storage device. When the device enters an area without a network, the user can manually install the update package to keep the device's hardware signature library up to date. Facilitating the use of the device in an environment without a network means allowing the user to pre-download the update package of the hardware signature library when there is a network, and manually install the update when the device is in an environment without a network. This ensures that the malicious application detection function can be used normally in different network environments.
[0061] In this way, updating the hardware signature code library according to preset rules can ensure the real-time and accuracy of the library. The hardware signature code library can be updated regularly or dynamically according to actual conditions to include the latest device information, thereby improving the performance and reliability of the detection system.
[0062] In some optional implementations, storing and retrieving hardware feature codes based on a hash algorithm includes: if a hash value calculated based on the hash algorithm is a preset hash value, and the data of the hardware feature codes in the hardware feature code library exceeds a preset quantity, executing a preset optimization strategy.
[0063] In this embodiment, if the hash value calculated based on the hash algorithm is a preset hash value K1, and the number of entries N1 in the hardware feature code library exceeds the preset number, additional measures can be taken to avoid high-probability hash conflicts caused by an overly large hash table. K1 represents a specific hash value, and N1 represents the number of feature codes already stored in the library. For example, assuming that there are 1500 feature code entries in the current library, and the hash value calculated by a certain device is exactly K1, the system will automatically start the optimization strategy S1, which may include but is not limited to using a larger hash table or a more complex hash function, such as SHA-512, to reduce the possibility of hash collisions. Through this optimization, efficient hash operation performance can be maintained even when the library is large.
[0064] Among them, the preset number can be set to 1000. The selection of 1000 as the threshold for triggering the optimization strategy is based on experience. When the number of signatures in the library is less than 1000, the hash table can usually maintain good performance, but after exceeding 1000, the probability of hash collision will increase significantly. Therefore, setting this threshold to 1000 is a choice that balances system performance and resource consumption. In addition, the use of the K1 condition is to take targeted optimization measures when a specific hash value appears, rather than optimizing all situations, thereby avoiding unnecessary computational overhead.
[0065] In some optional implementations, the hash value can be uniformly distributed by selecting a hash function. Specifically, a hash function with good hash properties can be selected so that different input data can generate different hash values as much as possible. For example, the SHA-256 hash algorithm can be used. This algorithm can generate a 256-bit hash value with strong uniformity. Selecting such a hash function can effectively prevent conflicts between malicious applications in the hash space, thereby reducing the probability of collision and improving detection accuracy.
[0066] In some optional implementations, the hardware signature library can also be updated through an incremental update strategy. When a new malicious application signature needs to be added to the hash library, only the newly added part is updated. For example, the existing malicious application library contains 10,000 signatures, and 10 new signatures are added. At this time, only the 10 newly added signatures need to be hashed and the index updated, without the need to reprocess all 10,001 signatures.
[0067] In this way, the incremental update strategy can avoid updating the entire hardware signature library every time, which can significantly reduce the amount of calculation, improve the response speed, and improve the data collection efficiency.
[0068] In some optional implementations, the hash value calculated by the hash algorithm is cached. For example, when a known malicious application is detected, if the hash value of the application already exists in the cache, it is directly read from the cache without calling the hash function again for calculation.
[0069] In this way, repeated calculation of the hash value of the same data in multiple operations can be avoided, and repeated calculations can be reduced, which not only speeds up the detection speed but also saves computing resources.
[0070] In some optional implementations, if the hash value of the hash function is distributed within a preset interval and the current data volume is greater than a critical value, the hash space is reallocated. The preset interval is [A1, B1], A1 represents the minimum value of the current hash value, and B1 represents the maximum value of the current hash value. The current data volume can be represented by L1, and the critical value can be represented by C1.
[0071] In this embodiment, when L1 exceeds C1, it indicates that the current hash space is not enough to accommodate new data, and the space size of the hash table needs to be increased to ensure that new data can be effectively stored and searched. For example, if the initial hash table space size is 10,000 slots, the critical value C1 is set to 8,000. When the actual amount of data stored reaches 8,001, the system automatically adjusts the space size of the hash table to 20,000 slots to ensure that subsequent data can be smoothly inserted while maintaining a uniform distribution of hash values. In this way, the performance degradation problem caused by insufficient hash table space can be effectively prevented.
[0072] In some optional implementations, high-bandwidth transmission technology is used to obtain terminal operating parameter information, including: determining a transmission channel; compressing data in transmission; performing multipath transmission during data transmission; and transmitting data in segments if it is detected that the current available bandwidth is less than a preset bandwidth threshold and the length of the task queue waiting to be processed exceeds a preset length threshold.
[0073] In this embodiment, a transmission channel is determined. One or more channels can be dynamically selected from multiple possible transmission paths according to the real-time conditions of the current network environment. The network conditions here include but are not limited to network delay, packet loss rate and bandwidth. Through this selection, the efficiency and stability of data transmission can be ensured. For example, when the terminal device attempts to upload the collected terminal operation parameter information to the cloud, it can automatically detect the currently available WLAN and 4G networks, and select a WLAN with low delay and large bandwidth as the transmission channel.
[0074] Compress the data in transmission. The malicious application signature database to be transmitted can be compressed by ZIP or other efficient algorithms, reducing the original file from 100MB to 30MB, greatly improving the upload efficiency and saving the user's traffic cost. The compression ratio can be expressed as the ratio of the data size before compression to the data size after compression. It can reduce the amount of data required during the transmission process, thereby reducing the occupation of network resources and speeding up data transmission.
[0075] During the data transmission process, multi-path transmission is performed. Different parts of the detected application can be sent out through multiple available links at the same time. If a blockage occurs on a link, the remaining links can take over the remaining untransmitted data packets. In this way, the reliability of the data transmission process can be enhanced. Even if a path fails, the remaining paths can continue to work, ensuring that the overall transmission task is completed smoothly and ensuring that the entire detection process is not affected by single point failures, thereby achieving a more stable network connection.
[0076] If it is detected that the current available bandwidth B2 is less than the preset bandwidth threshold T2, and the length of the task queue waiting to be processed Q2 exceeds the preset length threshold T3, data segment transmission is performed. The most suitable data packet size D and number N in the current situation are calculated. The specific values of these parameters depend on the actual values of B2 and Q2 and the hardware processing capacity. Generally speaking, D is inversely proportional to N, that is, as N increases, in order to keep the total data volume unchanged, each packet should be smaller; vice versa. For example, when B2 is lower than 5Mbps and Q2 reaches 100, the log file of the application to be transmitted may be cut into small blocks of 20KB and transmitted separately until all uploads are completed or the number of tasks in the waiting list drops to a safe range. The total data volume S = N × D, where S is fixed, and N and D can be dynamically adjusted according to actual conditions. It can balance the relationship between transmission efficiency and resource consumption, while meeting the needs of different network environments.
[0077] This can avoid data backlogs caused by slow networks or overloaded servers, relieve bandwidth pressure, and improve response speed.
[0078] In some optional embodiments, based on the data acquisition protocol, terminal operating parameter information is obtained by multiple threads, including: detecting the current available data transmission channels, evaluating the data delay and packet loss rate of each channel; determining the target data transmission channel, wherein the target data transmission channel is the data transmission channel with the smallest data delay among the available data transmission channels with a packet loss rate lower than a preset packet loss threshold; based on the target data transmission channel, the terminal operating parameter information is transmitted.
[0079] In this embodiment, the currently available data transmission channels are detected, and the data delay and packet loss rate of each channel are evaluated. All channels that may be used for data transmission in the network environment can be obtained, and the actual performance of these channels can be measured by Ping command or TCP handshake test. The performance indicators of each channel, including data delay and packet loss rate, are crucial to ensure reliable data transmission. For example, by initiating network connection requests on different servers, the round-trip time of each connection and the proportion of unresponded requests can be collected to obtain specific delay and packet loss rate values.
[0080] Determine the target data transmission channel, and select the channel with the minimum delay and packet loss rate below the threshold for data transmission. The data delay can be P, and the packet loss rate can be D. The maximum allowed data delay can be set to P2, and the threshold of the packet loss rate can be D2. The specific values of P and D vary depending on the application scenario. You can set P2≤100 milliseconds and D2≤1%. When selecting, you can first filter out channels with packet loss rates D>D2, and then select the channel with the minimum delay P from the remaining channels. Specifically, if there is a WiFi channel with P=80 milliseconds, D=0.5%, and a 4G channel with P=150 milliseconds, D=0.8%, the system will select the WiFi channel as the optimal transmission channel.
[0081] In this way, low latency and low packet loss rate can ensure the fast and reliable data transmission.
[0082] In some optional embodiments, the transmission channel can be switched dynamically. By continuously monitoring the performance of each transmission channel, the channel used can be automatically adjusted. All channels can be re-evaluated according to a preset period to decide whether to switch to a channel with better performance. The preset period can be set to once every 10 seconds. Specifically, if the performance of the initially selected WiFi channel degrades due to environmental interference, and the 4G channel becomes more stable, the system will automatically switch to the 4G channel to ensure the best transmission effect.
[0083] In this way, it can adapt to scenarios where the network environment changes frequently.
[0084] In some optional embodiments, the aforementioned method for application detection also includes, in the process of transmitting terminal operating parameter information, if the packet loss rate of the target data transmission channel is higher than or equal to a preset packet loss threshold, or the data delay of the target data transmission channel is greater than a maximum data delay threshold, re-determining a new target data transmission channel.
[0085] In this embodiment, if it is detected that the packet loss rate D1 of the target data transmission channel exceeds the threshold value D2, and the delay P1 is greater than the maximum allowable value P2, it will immediately switch to the alternative channel. This is an emergency measure to deal with sudden network problems. When the current main channel suddenly performs poorly, you can switch to the alternative channel to continue transmission to prevent data loss or interruption. For example, in one detection, it was found that the D1 of the WiFi channel reached 2%, and P1 reached 120 milliseconds, exceeding the preset limits of D2=1% and P2=100 milliseconds. At this time, the system will immediately switch to the 4G channel with more stable performance. In this way, it is ensured that data can be transmitted continuously and reliably even in the event of an abnormality in the network environment.
[0086] The above steps combined with dynamic monitoring and timely adjustment mechanisms can significantly improve the efficiency and reliability of data transmission, and are particularly suitable for application scenarios with high requirements for real-time and accuracy, such as data upload and download in application detection.
[0087] In some optional embodiments, detecting the currently available data transmission channel includes: evaluating network delay through a ping test; detecting packet loss information in the path based on a traceroute tool; monitoring the performance indicators of each transmission channel; if the average delay L1 of the Ping test is greater than a threshold value L2, and the number of path hops J1 detected by the traceroute tool exceeds a critical value J2, then marking the channel as a high-risk channel and not recommended for use.
[0088] In this embodiment, the network latency is evaluated by a ping test, which measures the time required for a data packet to be sent from a source device to a target device and back. The average latency L1 is calculated by sending a series of small data packets and recording the round-trip time of each packet. The response speed of the network can be understood. For example, a Ping test was performed on an Android device suspected of being infected with malware, and it was found that under normal circumstances, the average latency for communicating with the cloud server was about 20 milliseconds, while when the malware was active, the latency could increase to 50 milliseconds.
[0089] Detect packet loss information in the path based on the traceroute tool. The traceroute tool can display the number of hops and corresponding time of all intermediate routers that the data packet passes through to reach the destination. By checking whether there is packet loss at each hop in the path, the reliability of the network path can be determined. Specifically, if a large number of packets are lost at a certain hop, it means that there may be a network failure or interference by malicious behavior. For example, when an Android device is connected to the Internet, if traceroute detects a packet loss rate of 10% at a certain hop, this may be a sign of malware activity.
[0090] Monitor the performance indicators of each transmission channel, including bandwidth utilization and stability. This can be achieved by continuously collecting and analyzing network traffic data. Monitoring bandwidth utilization can help you understand the use of network resources, while monitoring stability can help you detect sudden abnormal changes. For example, you can use a third-party network monitoring tool or Android's built-in traffic statistics function to record the data throughput and error rate per second. If the bandwidth utilization continues to exceed 90%, or the error rate suddenly increases, these may be abnormal manifestations caused by malware in network activity.
[0091] If the average delay L1 of the Ping test is greater than the threshold L2, and the number of path hops J1 detected by the traceroute tool exceeds the critical value J2, the channel is marked as a high-risk channel and is not recommended. Among them, the threshold L2 is a preset maximum acceptable delay time, which is usually determined according to the specific application scenario. The critical value J2 is a maximum allowed number of path hops, which is used to evaluate the complexity and potential risks of the network path. The selection of these two thresholds requires a trade-off between detection accuracy and system performance. For example, for Android applications, L2 can be set to 50 milliseconds and J2 can be set to 10 hops. If the average delay of a network connection exceeds 50 milliseconds and the number of hops passed exceeds 10 hops, the connection is considered high-risk and the system will advise users to avoid transmitting sensitive data through this path.
[0092] In this way, the accuracy and timeliness of the detection system can be ensured while minimizing the impact on normal application performance. By comprehensively using a variety of technical means, the security status of the network environment can be more comprehensively assessed, thereby effectively resisting potential malicious attacks.
[0093] In some optional implementations, network delay can be evaluated based on a Ping test, including: sending an ICMP echo request and receiving an ICMP echo reply; recording the sending time of each request and the receiving time of the reply, and calculating the delay; selecting the average delay of three consecutive requests as the final delay value; if the calculated delay D2 is less than a threshold value T4, and the number of packet losses F1 in three consecutive requests is 0, marking the current channel as a reliable channel.
[0094] In this embodiment, sending an ICMP echo request and receiving an ICMP echo reply includes: sending an ICMP Echo Request data packet to a target server and waiting for it to return an ICMP Echo Reply data packet. Through the exchange of such requests and replies, the round-trip time of a data packet in the network can be measured.
[0095] Record the sending time of each request and the receiving time of the response, and calculate the delay, including: when the ICMP Echo Reply returns, record the time difference from sending the ICMP Echo Request to receiving the ICMP Echo Reply, that is, the round trip time (RTT), which is the delay of this transmission. For example, if a request is sent at 10:00:00.000 and the response is received at 10:00:01.000, the delay of this request is 1000 milliseconds.
[0096] Select the average delay of three consecutive requests as the final delay value. For example, the delays of three consecutive requests are 1000 milliseconds, 980 milliseconds, and 1020 milliseconds, respectively. Then the final delay value calculation formula is (D1+D2+D3) / 3=(1000+980+1020) / 3=1000 milliseconds. In this formula, D1, D2, and D3 represent the delays of three consecutive requests, ranging from tens of milliseconds to thousands of milliseconds. The optimal value depends on the specific network environment. Usually, when the network conditions are good, the average delay will be lower. In this way, instead of relying on the delay result of a single request, taking the average delay of three consecutive requests as the final delay value can improve the accuracy and stability of the evaluation.
[0097] If the calculated delay D2 is less than the threshold T4, and the number of packet losses F1 in three consecutive requests is 0, the current channel is marked as a reliable channel. The threshold T4 can be set to determine whether the current network channel is a reliable channel. Specifically, if the delay D2 calculated in the above steps is less than the set threshold T4, and there is no packet loss in these three consecutive Ping tests (F1=0), the network channel is determined to be a reliable channel. For example, if the threshold T4 is set to 100 milliseconds, all packets in the three requests are successfully returned, and the calculated final delay is 98 milliseconds, then the condition is met to mark this channel as reliable. The threshold T4 is usually set according to different application scenarios, and the optimal value depends on the specific usage requirements and network environment. In most cases, a lower threshold means higher requirements for network quality, while a higher threshold can accept a certain degree of delay.
[0098] Thus, suppose the detection system needs to ensure that data packets can be reliably transmitted to the remote server within a certain period of time to verify whether the application is affected by malicious behavior. If the data transmission channel requested by an application is considered unreliable, that is, high latency or packet loss, it may be interfered by malware, and the system can further analyze and inspect the application.
[0099] In some optional embodiments, application detection results are generated based on terminal operating parameter information, user operations and terminal operating temperature information, including: converting the terminal operating parameter information, user operations and terminal operating temperature information into a preset data format; extracting numerical features and classification features from data in the preset data format; identifying abnormal patterns based on the numerical features and classification features to obtain recognition results; and generating application detection results based on the recognition results.
[0100] In this embodiment, a unified data format can be defined to store all types of information, such as JSON, XML or CSV, etc. The unified data format can flexibly represent numerical data, such as CPU usage, memory usage or temperature, etc., and text data, such as user operation descriptions or timestamps, etc.
[0101] Extract numerical and categorical features from standardized data, which can be used for subsequent machine learning and statistical analysis. For example, you can extract CPU usage, memory usage, temperature change rate, etc. as numerical features, and extract the frequency and type of user operations as text or categorical features. Use machine learning and statistical methods to analyze data and identify abnormal patterns or trends. For example, you can use box plots to detect outliers, and use time series analysis to identify periodic changes in temperature or resource usage. Generate detailed application detection results based on the identification results. Application detection results can include a specific description of the abnormal behavior, the time of occurrence, the resources or user operations affected, as well as possible risk assessments and recommended countermeasures.
[0102] Specifically, if an application continuously requests permissions or sends abnormal data packets, it will be considered suspicious behavior; at the same time, combined with the comparative analysis of the historical sample library, it can further confirm whether there is a real threat, as well as the specific level and degree of harm of the threat.
[0103] In some optional embodiments, if the terminal operating temperature represented by the terminal operating temperature information exceeds a preset temperature threshold, the terminal operating parameter information is corrected, including: when the terminal operating temperature represented by the terminal operating temperature information exceeds the preset temperature threshold, the terminal operating parameter information is obtained; and the terminal operating parameter information is weighted or smoothed and filtered to correct the terminal operating parameter information.
[0104] In this embodiment, when the terminal operating temperature represented by the terminal operating temperature information exceeds the preset temperature threshold, the correction program can be automatically started to perform weighted processing or smoothing on the affected data stream. Specifically, when used outdoors in the hot summer, the mobile phone may be in a high temperature state for a long time, which may cause some sensors to have reduced sensitivity or increased false alarms; by correcting the affected data, these problems can be effectively alleviated to ensure the reliability and accuracy of the entire detection process.
[0105] In this embodiment, a device for application detection is also provided, which is used to implement the above-mentioned embodiments and preferred implementation modes, and the descriptions that have been made will not be repeated. As used below, the term "module" can implement a combination of software and / or hardware of a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.
[0106] This embodiment provides a device for application detection. Figure 2 A schematic diagram of the structure of an apparatus for application program detection according to an embodiment of the present invention is shown. Figure 2 As shown, including:
[0107] The first acquisition module 201 is used to acquire terminal operation parameter information when the application is in operation; if the terminal operation parameter represented by the terminal operation parameter information exceeds a preset parameter threshold, the terminal operation parameter information and the user operation are recorded.
[0108] In this embodiment, the first acquisition module 201 collects hardware parameters from various sensors of the mobile terminal device, such as CPU usage, memory usage, network traffic, etc. This process relies on highly sensitive sensors to capture the real-time operating status of the device for subsequent analysis and judgment. In order to solve the physical limitations of the hardware interface, the first acquisition module 201 is designed with a multi-channel parallel processing mechanism, which can quickly switch and read data between multiple sensors, greatly improving the speed and quality of data acquisition. For example, in an actual application, when a sudden surge in CPU usage is detected without obvious user activity, the first acquisition module 201 can quickly capture this abnormal signal and record it for subsequent analysis.
[0109] The second acquisition module 202 is used to acquire the terminal operation temperature information when the application is in the running state; if the terminal operation temperature represented by the terminal operation temperature information exceeds a preset temperature threshold, the terminal operation parameter information is corrected.
[0110] The second acquisition module 202 is equipped with a high-precision temperature sensing chip and an adaptive adjustment algorithm, which can monitor and record the temperature information of the core components of the device in real time. During the data collection and processing process, temperature fluctuations will have a significant impact on the hardware performance and may cause inaccurate detection data. In order to solve this problem, the second acquisition module 202 is embedded in the first acquisition module 201. The second acquisition module 202 can monitor the hardware operating temperature in real time and dynamically correct the collected data according to the temperature control model to ensure that high-precision data support can be provided even in an environment with large temperature changes.
[0111] The detection module 203 is used to generate an application detection result based on the terminal operation parameter information, the user operation and the terminal operation temperature information.
[0112] The detection module 203 is connected to the above modules by wired or wireless means to receive and analyze the collected multi-source data. The detection module 203 uses a data analysis algorithm to integrate and judge abnormalities of the data, and finally generates the detection results of the application. The detection results include potential risk points, helping users to discover and respond to malicious applications in a timely manner and improve the security of mobile devices.
[0113] In a large-scale screening of popular downloaded applications on the market, the detection module 203 successfully identified and blocked hundreds of malicious software with features such as hidden installation and privacy theft, greatly ensuring the user's network security.
[0114] In the related technology, the internal structures of mobile phones of different brands and models vary greatly, which may cause the detection algorithm to fail to run accurately on some devices.
[0115] In some optional implementations, an adapter module may be provided between the first acquisition module or the second acquisition module and the detection module. The adapter module is compatible with mobile devices of various brands and models, ensuring that the detection method can run stably on different devices, thereby solving the problem that differences in the internal structures of the devices affect the accuracy of the algorithm.
[0116] In this embodiment, the adapter module is a middleware connected between the data acquisition module and the device hardware, which is designed to solve the problem of inaccurate algorithms caused by differences in the internal structures of mobile phones of different brands and models. The adapter module can intelligently identify and match various hardware interfaces by building in a series of predefined protocols and rule libraries, thereby ensuring seamless docking and smooth data transmission on any device. For example, in a field test, the adapter module successfully applied a set of detection algorithms optimized based on the Samsung Galaxy series to the Huawei P40 mobile phone, and achieved satisfactory detection results, proving its strong cross-platform adaptability.
[0117] The adapter module can be compatible with various brands and models of devices through preset adapters. The adapter module can automatically identify and configure the transmission and interface parameters suitable for the current device, avoiding algorithm accuracy problems caused by internal structure differences.
[0118] In some optional implementations, the first acquisition module 201 includes:
[0119] The first unit of the first acquisition module is used to determine the data acquisition protocol based on the hardware interface type of the terminal; based on the data acquisition protocol, multi-threadedly acquire the terminal operation parameter information; wherein the data acquisition protocol includes a data acquisition frequency and a data verification frequency.
[0120] In some optional implementations, the first unit of the first acquisition module includes:
[0121] The first subunit of the first acquisition module is used to determine the hardware interface type based on the hardware feature code library; based on the hardware interface type, load the data acquisition driver corresponding to the hardware interface type; if the hardware interface type is a preset hardware interface type and the data acquisition driver is a preset data acquisition driver, increase the data verification frequency.
[0122] In some optional embodiments, the aforementioned device for application detection also includes: a data acquisition module for storing and retrieving hardware feature codes based on a hash algorithm; updating the hardware feature code library based on one or more of the following methods: obtaining new hardware feature codes according to a preset period based on an automated script, and adding the new hardware feature codes to the hardware feature code library; deleting invalid hardware feature codes in the hardware feature code library; marking invalid hardware feature codes in the hardware feature code library; and updating the hardware feature code library offline.
[0123] In some optional implementations, the first acquisition module first unit further includes:
[0124] The second subunit of the first acquisition module is used to detect the current available data transmission channels, evaluate the data delay and packet loss rate of each channel; determine the target data transmission channel, wherein the target data transmission channel is the data transmission channel with the smallest data delay among the available data transmission channels with a packet loss rate lower than a preset packet loss threshold; based on the target data transmission channel, transmit terminal operation parameter information.
[0125] In some optional embodiments, the second subunit of the first acquisition module is also used to re-determine a new target data transmission channel if, during the process of transmitting terminal operating parameter information, the packet loss rate of the target data transmission channel is higher than or equal to a preset packet loss threshold, or the data delay of the target data transmission channel is greater than a maximum data delay threshold.
[0126] In some optional implementations, the detection module 203 includes:
[0127] The detection unit is used to convert terminal operation parameter information, user operation and terminal operation temperature information into a preset data format; extract numerical features and classification features from data in the preset data format; identify abnormal patterns based on the numerical features and classification features to obtain recognition results; generate application detection results based on the recognition results.
[0128] In some optional implementations, the second acquisition module 202 includes:
[0129] The first unit of the second acquisition module is used to acquire terminal operation parameter information when the terminal operation temperature represented by the terminal operation temperature information exceeds a preset temperature threshold; perform weighted or smooth filtering processing on the terminal operation parameter information to correct the terminal operation parameter information.
[0130] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.
[0131] The device for application detection in this embodiment is presented in the form of a functional unit, where the unit refers to an application specific integrated circuit (ASIC) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.
[0132] The embodiment of the present invention also provides a computer device having the above Figure 2 An apparatus for application detection is shown.
[0133] See also Figure 3 , Figure 3 is a schematic diagram of the structure of a computer device provided by an optional embodiment of the present invention, such as Figure 3 As shown, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components are connected to each other using different buses for communication, and can be installed on a common mainboard or installed in other ways as needed. The processor can process instructions executed in the computer device, including instructions stored in or on the memory to display graphical information of a graphical user interface on an external input / output device (such as a display device coupled to an interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Similarly, multiple computer devices can be connected, and each device provides some necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 3 A processor 10 is taken as an example.
[0134] The processor 10 may be a central processing unit, a network processor or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be a dedicated integrated circuit, a programmable logic device or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic or any combination thereof.
[0135] The aforementioned memory 20 stores instructions executable by at least one processor 10, so that the aforementioned at least one processor 10 executes the method shown in the above embodiment.
[0136] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data created according to the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely arranged relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0137] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid state drive; the memory 20 may also include a combination of the above types of memory.
[0138] The computer device also includes an input device 30 and an output device 40. The processor 10, the memory 20, the input device 30 and the output device 40 may be connected via a bus or other means. Figure 3 The example of connecting through bus is taken in the following.
[0139] The input device 30 can receive input digital or character information, and generate key signal input related to the user settings and function control of the computer device, such as a touch screen, a keypad, a mouse, a track pad, a touch pad, an indicator rod, one or more mouse buttons, a trackball, a joystick, etc. The output device 40 may include a display device, an auxiliary lighting device (such as a light emitting diode) and a tactile feedback device (such as a vibration motor), etc. The above-mentioned display device includes but is not limited to a liquid crystal display, a light emitting diode, a display and a plasma display. In some optional embodiments, the display device can be a touch screen.
[0140] The embodiment of the present invention also provides a computer-readable storage medium. The method according to the embodiment of the present invention can be implemented in hardware, firmware, or can be implemented as a computer code that can be recorded in a storage medium, or can be implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and will be stored in a local storage medium through a network download, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state hard disk, etc.; further, the storage medium can also include a combination of the above types of memories. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor, or hardware, the method shown in the above embodiment is implemented.
[0141] A part of the present invention may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present invention through the operation of the computer. Those skilled in the art should understand that the existence of the computer program instruction in a computer-readable medium includes, but is not limited to, a source file, an executable file, an installation package file, etc., and accordingly, the way in which the computer program instruction is executed by the computer includes, but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium may be any available computer-readable storage medium or communication medium accessible to the computer.
[0142] Although the embodiments of the present invention have been described in conjunction with the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations are all within the scope defined by the appended claims.
Claims
1. A method for application detection, characterized in that The method comprises: Acquire terminal operation parameter information when the application is in operation, and if the terminal operation parameter represented by the terminal operation parameter information exceeds a preset parameter threshold, record the terminal operation parameter information and the user operation; Acquire terminal operating temperature information when the application is in a running state, and if the terminal operating temperature represented by the terminal operating temperature information exceeds a preset temperature threshold, modify the terminal operating parameter information; An application program detection result is generated based on the terminal operation parameter information, the user operation and the terminal operation temperature information.
2. The method according to claim 1, characterized in that The obtaining of terminal operation parameter information when the application is in the running state includes: Determining a data acquisition protocol based on the hardware interface type of the terminal; Based on the data acquisition protocol, multi-threading obtains the terminal operation parameter information; Wherein, the data collection protocol includes data collection frequency and data verification frequency.
3. The method according to claim 2, characterized in that The determining of the data acquisition protocol based on the hardware interface type of the terminal includes: Determining the hardware interface type based on a hardware feature code library; Based on the hardware interface type, loading a data acquisition driver corresponding to the hardware interface type; If the hardware interface type is a preset hardware interface type, and the data acquisition driver is a preset data acquisition driver, the data verification frequency is increased.
4. The method according to claim 3, characterized in that The method further comprises: Store and retrieve hardware signatures based on hash algorithms; The hardware signature database is updated based on one or more of the following methods: Based on the automated script, according to a preset period, a newly added hardware feature code is obtained, and the newly added hardware feature code is added to the hardware feature code library; Deleting invalid hardware feature codes in the hardware feature code library; marking invalid hardware feature codes in the hardware feature code library; and, The hardware signature database is updated offline.
5. The method according to claim 2, characterized in that: The multi-threaded acquisition of the terminal operation parameter information based on the data acquisition protocol includes: Detect the currently available data transmission channels and evaluate the data delay and packet loss rate of each channel; Determine a target data transmission channel, wherein the target data transmission channel is a data transmission channel with the smallest data delay among the available data transmission channels whose packet loss rate is lower than a preset packet loss threshold; The terminal operation parameter information is transmitted based on the target data transmission channel.
6. The method according to claim 5, characterized in that The method further comprises: During the transmission of the terminal operation parameter information, if the packet loss rate of the target data transmission channel is higher than or equal to the preset packet loss threshold, or the data delay of the target data transmission channel is greater than the maximum data delay threshold, a new target data transmission channel is re-determined.
7. The method according to claim 1, characterized in that The generating the application detection result based on the terminal operation parameter information, the user operation and the terminal operation temperature information includes: Converting the terminal operation parameter information, the user operation and the terminal operation temperature information into a preset data format; Extract numerical features and categorical features from data in a preset data format; Based on the numerical features and the classification features, identifying abnormal patterns and obtaining identification results; Based on the recognition result, the application detection result is generated.
8. The method according to claim 1, characterized in that If the terminal operating temperature represented by the terminal operating temperature information exceeds a preset temperature threshold, correcting the terminal operating parameter information includes: When the terminal operating temperature represented by the terminal operating temperature information exceeds a preset temperature threshold, acquiring the terminal operating parameter information; The terminal operation parameter information is weighted or smoothed and filtered to correct the terminal operation parameter information.
9. A device for application detection, characterized in that: The device comprises: A first acquisition module is used to acquire terminal operation parameter information when the application is in operation; if the terminal operation parameter represented by the terminal operation parameter information exceeds a preset parameter threshold, the terminal operation parameter information and the user operation are recorded; The second acquisition module is used to obtain the terminal operation temperature information when the application is in the running state; if the terminal operation temperature represented by the terminal operation temperature information exceeds the preset temperature threshold, the terminal operation parameter information is corrected; The detection module is used to generate an application detection result based on the terminal operation parameter information, the user operation and the terminal operation temperature information.
10. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the method for application detection according to any one of claims 1 to 8 by executing the computer instructions.