Method, system and equipment for identifying injection risk in data acquisition process and medium

By acquiring and analyzing the call stack information of the data acquisition service, identifying the risk of injection in the data acquisition process, it solves the problem of difficulty in dealing with injection attacks in the data acquisition process in the prior art and improves the security of the system.

CN119989366APending Publication Date: 2025-05-13ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510104511.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-22
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The prior art is difficult to effectively deal with injection attacks during data acquisition, resulting in poor system security.

Method used

By obtaining the call stack information of the data collection service and using this information to identify risks, we determine whether there is an injection risk during the execution of the data collection service.

Benefits of technology

The ability to identify the risk of injection during data collection is realized, the serious impact of injection attacks on subsequent operations and decisions is avoided, and the security of the system is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989366A_ABST
    Figure CN119989366A_ABST
Patent Text Reader

Abstract

The invention provides a method, a system, equipment and a medium for identifying an injection risk in a data acquisition process. The method comprises the steps that call stack information corresponding to a data collection service is obtained, and the call stack information is recorded for a function used for executing the data collection service in the process of executing the data collection service; and risk identification is carried out based on the call stack information to obtain an identification result, and the identification result is used for representing whether an injection risk exists in the process of executing the data acquisition service.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] One or more embodiments of the present specification relate to the field of information security technology, and in particular, to a method, system, device, and medium for identifying injection risks during data collection. Background Art

[0002] As the services provided by terminal applications become more and more diverse, the security threats they face are also increasing, especially injection attacks against the data collection process. By injecting attacks into the data collection process, the data collected during the data collection process can be tampered with, which will have a serious impact on a series of subsequent operations and decisions. For example, in the face-swiping payment scenario, by tampering with the facial data collected by the terminal with the facial data of other users, resources in other users' accounts can be stolen, causing economic losses to other users.

[0003] At present, the protection measures taken against security threats are mostly focused on data transmission security and data storage security. They do improve the security of the system to a certain extent, but they are often unable to effectively deal with the security risks of the data collection process within the application, resulting in poor security. Summary of the invention

[0004] In view of this, one or more embodiments of this specification provide the following technical solutions:

[0005] According to a first aspect of one or more embodiments of this specification, a method for identifying injection risks in a data collection process is provided, the method comprising:

[0006] Acquire call stack information corresponding to the data collection service, wherein the call stack information is call stack information recorded for a function used to execute the data collection service during the execution of the data collection service;

[0007] Risk identification is performed based on the call stack information to obtain an identification result, and the identification result is used to indicate whether there is an injection risk in the process of executing the data collection business.

[0008] According to a second aspect of one or more embodiments of this specification, a system for identifying injection risks in a data collection process is provided, the system comprising a client and a server;

[0009] The client is used to record call stack information for a function used to execute the data acquisition service during the execution of the data acquisition service, and send the call stack information to the server;

[0010] The server is used to receive the call stack information, perform risk identification based on the call stack information, and obtain an identification result, wherein the identification result is used to indicate whether there is an injection risk in the process of executing the data collection business.

[0011] According to a third aspect of one or more embodiments of this specification, an electronic device is proposed, comprising: a processor; a memory for storing processor-executable instructions; wherein the processor implements the steps of the method described in the first aspect by running the executable instructions.

[0012] According to a fourth aspect of one or more embodiments of the present specification, a computer-readable storage medium is provided, on which computer instructions are stored, and when the instructions are executed by a processor, the steps of the method described in the first aspect are implemented.

[0013] According to a fifth aspect of one or more embodiments of the present specification, a computer program product is proposed, comprising a computer program / instruction, wherein when the computer program / instruction is executed by a processor, the steps of the method described in the first aspect are implemented.

[0014] It can be seen from the above embodiments that this specification realizes the identification of whether there is an injection risk in the process of executing the data collection business by recording the call stack information of the function used to execute the data collection business during the execution of the data collection business. In this way, the identification result can be referred to when performing a series of operations and decisions based on the collected data subsequently, which can avoid the injection attack from having a serious impact on the subsequent series of operations and decisions, thereby improving the security of the system.

[0015] Since the call stack information is a stack structure formed by function calls when the program is executed, and records the calling order and parameters of the function, when an injection attack occurs, the injection attack will leave specific traces in the call stack information. Therefore, analyzing the call stack information can accurately determine whether there is an injection risk. In addition, combining the solution provided in this specification with other protection measures against security threats can cover the entire life cycle of data, cope with more complex and changeable security environments, and provide users with more secure and reliable security protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 This is a schematic diagram of the architecture of an injection risk identification service system provided by an exemplary embodiment.

[0017] Figure 2 It is a flow chart of a method for identifying injection risks in a data collection process provided by an exemplary embodiment.

[0018] Figure 3It is a flow chart of a method for identifying injection risks in a data collection process by monitoring only some functions, provided by an exemplary embodiment.

[0019] Figure 4 It is a flow chart of a method for performing face recognition service provided by an exemplary embodiment.

[0020] Figure 5 It is a flow chart of a method for an injection risk identification service system to identify injection risks in a data collection process, provided by an exemplary embodiment.

[0021] Figure 6 It is a structural schematic diagram of a device provided by an exemplary embodiment.

[0022] Figure 7 A block diagram of a device for identifying injection risks in a data collection process provided by an exemplary embodiment. DETAILED DESCRIPTION

[0023] The user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this manual are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0024] Here is an explanation of the relevant terms:

[0025] Injection attack: The act of illegally inserting malicious code or data into the system by tampering with or manipulating the data transmission process through technical means.

[0026] Function call stack information: When the program is executed, the stack structure formed by function calls records the function calling order and parameters.

[0027] Face Recognition SDK: A software development kit for implementing face recognition capabilities on mobile devices.

[0028] As the services provided by terminal applications become more and more diverse, the security threats they face are also increasing, especially injection attacks against the data collection process. By injecting attacks into the data collection process, the data collected during the data collection process can be tampered with, which will have a serious impact on a series of subsequent operations and decisions. For example, in the face-swiping payment scenario, by tampering with the facial data collected by the terminal with the facial data of other users, resources in other users' accounts (such as funds, points, redemption coupons, gift cards, etc.) can be stolen, causing economic losses to other users.

[0029] However, the current protection measures taken against security threats are mostly focused on data transmission security and data storage security. For example, encryption algorithms are used to encrypt transmitted or stored data, and the SSL (Secure Sockets Layer) / TLS (Transport Layer Security) protocol is used to ensure the security of the data transmission link. These protection measures do improve the security of the system to a certain extent, but these protection measures are often unable to effectively deal with the security risks of the data collection process within the application. The transmission and storage of forged or tampered data have a serious impact on a series of subsequent operations and decisions, resulting in poor security.

[0030] Based on this, this specification provides a protection measure for the data collection process, which can determine whether there is an injection risk in the process of executing the data collection business. In this way, the next step can be executed based on whether there is an injection risk in the process of executing the data collection business, avoiding the injection attack from having a serious impact on the subsequent series of operations and decisions, and improving the security of the system.

[0031] During implementation, first obtain the call stack information corresponding to the data collection business. The call stack information is the call stack information recorded for the function used to execute the data collection business during the execution of the data collection business. Then, perform risk identification based on the call stack information to obtain an identification result, which is used to indicate whether there is an injection risk in the process of executing the data collection business.

[0032] In the above technical solution, by recording the call stack information for the function used to execute the data collection business during the execution of the data collection business, it is possible to identify whether there is an injection risk in the process of executing the data collection business. In this way, the identification result can be referred to when performing a series of operations and decisions based on the collected data. This can avoid the injection attack from having a serious impact on the subsequent series of operations and decisions, thereby improving the security of the system.

[0033] Since the call stack information is a stack structure formed by function calls when the program is executed, which records the calling order and parameters of the functions, when an injection attack occurs, the injection attack will leave specific traces in the call stack information. Therefore, analyzing the call stack information can accurately determine whether there is an injection risk.

[0034] In addition, combining the solution provided in this manual with other protection measures against security threats can cover the entire life cycle of data, cope with more complex and changing security environments, and provide users with more secure and reliable security protection.

[0035] The method for identifying input risks in the data collection process provided in this specification can be applied to any data collection scenario. This specification does not limit this, and only uses the following two examples for illustrative purposes:

[0036] For example, it is applied to the collection scenario of physiological characteristic data:

[0037] Among them, physiological characteristic data can be physiological characteristic data such as face data, fingerprint data, iris data, etc. used for identity management, and can also be physiological characteristic data such as heart rate, blood pressure, blood oxygen saturation, body temperature, etc. used for health management. This specification does not limit the physiological characteristic data.

[0038] When collecting physiological characteristic data for identity management through data collection services, malicious users may inject malicious code or data into the program of the data collection service, tamper with the physiological characteristic data collected by the data collection service, and perform illegal identity management. If the method for identifying injection risks in the data collection process provided in this specification is adopted, it can be identified whether there is an injection risk in the process of executing the data collection service. If there is an injection risk, the collected physiological characteristic data may have been tampered with, and the collected physiological characteristic data can be judged invalid, so that identity management will not be performed on the physiological characteristic data, or the identity management based on the physiological characteristic data is judged invalid, thereby avoiding illegal identity management based on forged or tampered physiological characteristic data, and improving the security of identity management.

[0039] In the process of collecting physiological characteristic data for identification, malicious merchants may inject malicious code or data into the data collection business program, tamper with the physiological characteristic data collected by the data collection business, make the user think that their body is unhealthy, and then deceive the user into buying the corresponding goods. If the method for identifying injection risks in the data collection process provided in this specification is adopted, it can be identified whether there is an injection risk in the process of executing the data collection business. If there is an injection risk, the collected physiological characteristic data may be forged or tampered with. The identification result is displayed to the user, which can prevent the user from being deceived by malicious merchants.

[0040] Another example is the collection scenario of environmental data:

[0041] Taking the environmental data captured by the camera as an example, in order to avoid the illegal behavior being recorded by the camera, malicious personnel may inject malicious code or data into the camera to tamper with the environmental data captured by the camera. If the method of identifying the injection risk in the data collection process provided in this manual is adopted, it can be timely discovered whether the environmental data captured by the camera has been tampered with, and the problem can be solved as soon as possible, thereby improving the security of the camera.

[0042] It should be noted that the data collection service in this specification may be a service that only collects data, or may be a service that not only collects data but also processes the collected data. For example, the data collection service may be a face recognition service that can collect face data, identify whether the collected face data is a complete face, instruct the user to blink, turn the head, etc., and determine whether the user has completed the operation based on the collected face data.

[0043] The following is an example of the application scenario of the face recognition service:

[0044] When performing face recognition, malicious users may forge face data and replace the face data collected by the camera with forged face data through injection attacks. Alternatively, malicious users may use a photo of the target face for face recognition. When the client instructs the user to blink or turn the head, the malicious user may tamper with the photo data collected by the client through injection attacks to simulate the effects of blinking and turning the head. Alternatively, malicious users may attack the face feature recognition function of the face recognition service through injection attacks and falsely report the existence of a face when no face exists, or falsely report that a corresponding operation has been performed when the collected face has not, or falsely report that the collected face is the target face when the collected face is not the target face.

[0045] If the method for identifying injection risks in the data collection process provided in this specification is adopted, during the execution of the face recognition service, the call stack information recorded by the function used to execute the face recognition service can be used to identify risks based on the call stack information to obtain an identification result, which is used to indicate whether there is an injection risk during the execution of the face recognition service. In this way, no matter where the malicious user carries out the injection attack in the face recognition process, it can be identified, thereby improving the security of face recognition.

[0046] It should be noted that this specification only provides an illustrative description of the application scenarios of the method for identifying input risks in the data collection process, and does not limit it.

[0047] In an illustrated embodiment, the execution subject of the method for identifying injection risks in the data collection process provided in this specification is an electronic device. The electronic device can be a mobile terminal such as a mobile phone, a tablet device, a PDA (Personal Digital Assistants), a wearable device (such as smart glasses, smart watches, etc.), and this specification does not limit this.

[0048] Exemplarily, an electronic device executes a data collection service. During the process of executing the data collection service, call stack information is recorded for a function used to execute the data collection service, and risk identification is performed based on the call stack information to obtain an identification result. The identification result is used to indicate whether there is an injection risk during the process of executing the data collection service.

[0049] In another illustrated embodiment, the execution subject of the method for identifying injection risks in the data collection process provided in this specification is a server. The server may be a physical server including an independent host, or the server may be a virtual server carried by a host cluster.

[0050] Exemplarily, the server obtains call stack information corresponding to the data collection service, which is call stack information recorded for the function used to execute the data collection service during the execution of the data collection service, and performs risk identification based on the call stack information to obtain an identification result, which is used to indicate whether there is an injection risk during the execution of the data collection service.

[0051] In another illustrated embodiment, the execution subject of the method for identifying injection risks in the data collection process provided in this specification is a system for identifying injection risks in the data collection process, which system may be Figure 1 The system shown.

[0052] Figure 1 FIG. 1 is a schematic diagram of an architecture of a system for identifying injection risks during data collection provided by an exemplary embodiment. Figure 1 As shown, the system may include a server (such as a server 11) and a client (such as an electronic device 12). There may be several clients.

[0053] The electronic device 12 can be an electronic device such as a mobile phone, a PDA (Personal Digital Assistants). Of course, mobile phones and PDAs are only some types of electronic devices that users can use. In fact, users can obviously also use electronic devices such as the following types: tablet devices, laptops, wearable devices (such as smart glasses, smart watches, etc.), etc., and one or more embodiments of this specification do not limit this. During operation, the electronic device 12 can run the program on the client side of the target application to implement the relevant functions of the target application. The target application can be any application with a data acquisition function. Of course, the target application can also have other functions, such as data processing function, data transmission function, data storage function, etc. This specification does not limit the functions of the target application. Exemplarily, the target application can be a face recognition application, a payment application, an e-commerce application, etc.

[0054] For example, when the electronic device 12 runs a program for an injection risk identification application, it can be implemented as a client of the injection risk identification application. For another example, when the electronic device 12 runs a program for a data collection application, it can be implemented as a client of the corresponding data collection application. For another example, when the electronic device 12 runs a program for a face recognition application, it can be implemented as a client of the corresponding face recognition application.

[0055] The application program on the client side of the target application can be started and run on the electronic device 12. The program on the client side can be a native application program installed on the terminal. Exemplarily, the solution provided in this specification is applicable to a client with an integrated face recognition SDK.

[0056] The server 11 may be a physical server including an independent host, or the server 11 may be a virtual server carried by a host cluster. During operation, the server 11 may run the server-side program of the target application to implement the relevant functions of the target application. For example, when the server 11 runs the server-side program of the injection risk identification application, it may be implemented as a corresponding injection risk identification service platform. For another example, when the server 11 runs the server-side program of the data collection application, it may be implemented as a corresponding data collection service platform. For another example, when the server 11 runs the server-side program of the face recognition application, it may be implemented as a corresponding face recognition service platform.

[0057] The service platform can interact with the client program of the target application running on the electronic device 12 to implement the function of the target application. For the network for interaction between the electronic device and the service platform, a wired or wireless network can be selected to implement communication based on the communication method supported by the corresponding electronic device, and this specification does not limit this. For example, if the electronic device can support both wired and wireless communication, then a wired or wireless network can be used to implement communication as needed; for another example, if the electronic device usually only supports wireless communication, then a wireless network can be used to implement communication.

[0058] It should be noted that the method for identifying injection risks during data collection provided in this specification is implemented through cooperation between the client and the server. This specification does not limit the specific steps performed by the client and the server, and only uses the following embodiments as examples for illustrative explanation.

[0059] In one illustrated embodiment, the client executes a data collection service, and records call stack information in the process of executing the data collection service. The server performs risk identification on the call stack information recorded by the client to determine whether there is an injection risk in the process of executing the data collection service. Among them, the client is used to record call stack information for the function used to execute the data collection service in the process of executing the data collection service, and send the call stack information to the server. The server is used to receive the call stack information, perform risk identification based on the call stack information, and obtain an identification result, and the identification result is used to indicate whether there is an injection risk in the process of executing the data collection service. In some embodiments, the server is used to perform the next operation or decision based on the identification result. In other embodiments, the server is used to send the identification result to the client; the client is used to receive the identification result and perform the next operation or decision based on the identification result.

[0060] In another illustrated embodiment, the client performs a data collection service, records call stack information in the process of performing the data collection service, performs risk identification based on the recorded call stack information, determines whether there is an injection risk in the process of performing the data collection service, and sends the identification result to the server, so that the server is informed of the injection risk of the client, so that the background technicians can update the client program in time to improve the security of the client side. Alternatively, the client sends the collected data and the identification result to the server, so that the server performs the next operation on the data based on the identification result corresponding to the data, such as judging that the data is invalid. Among them, the client is used to record the call stack information for the function used to perform the data collection service in the process of performing the data collection service, perform risk identification based on the call stack information, obtain the identification result, and send the identification result to the server, or send the collected data and the identification result to the server. The server is used to receive the identification result, or receive the data and the identification result.

[0061] In an illustrated embodiment, when the client records the call stack information in the process of executing the data collection service, the call stack information of only some functions is recorded. The call stack information includes the call stack information of the function to be monitored indicated by the monitoring indication information. In some embodiments, which part of the function is recorded is determined by the server. Among them, the client is used to send a monitoring indication acquisition request to the server in response to the start instruction of the data collection service, and the monitoring indication acquisition request is used to indicate the operating environment of the data collection service. The server is used to receive the monitoring indication acquisition request, generate monitoring indication information based on the operating environment of the data collection service, and return the monitoring indication information to the client based on the monitoring indication acquisition request. The function to be monitored is at least a part of the function used to execute the data collection service. The client is used to receive the monitoring indication information, and in the process of executing the data collection service, based on the monitoring indication information, record the call stack information for each function to be monitored.

[0062] In some embodiments, which part of the function is recorded is determined by the client. The client is used to respond to the start instruction of the data collection service, generate monitoring indication information based on the operating environment of the data collection service, and record call stack information for each function to be monitored based on the monitoring indication information during the execution of the data collection service. The function to be monitored is at least a part of the function used to execute the data collection service.

[0063] It should be noted that the monitoring indication information can be generated by the client or the server. This specification only takes the server generating the monitoring indication information as an example to illustrate the generation process of the monitoring indication information. Since the process of the client generating the monitoring indication information is similar to the process of the server generating the monitoring indication information, they will not be repeated here.

[0064] In one illustrated embodiment, the server is used to determine the risk level of a data collection service based on the operating environment of the data collection service; based on the risk level of the data collection service, monitoring indication information matching the risk level is determined from a plurality of alternative monitoring indication information, and the risk levels corresponding to the plurality of alternative monitoring indication information are positively correlated with the number of functions to be monitored indicated.

[0065] In another illustrated embodiment, the server is used to determine the risk level of the data collection service based on the operating environment of the data collection service; determine the number of functions that need to be monitored based on the risk level of the data collection service to obtain the monitoring number, wherein the monitoring number is positively correlated with the risk level; select the monitored number of key functions from the key functions used to execute the data collection service as the functions to be monitored; or, in descending order of probability of being attacked, select the monitored number of functions from the functions used to execute the data collection service as the monitoring functions; or, in descending order of importance, select the monitored number of functions from the functions used to execute the data collection service as the functions to be detected.

[0066] In another illustrated embodiment, the operating environment includes at least two environmental attributes of the current login account, device type, region, and application scenario. The server is used to determine the monitoring strategies corresponding to the at least two environmental attributes based on the at least two environmental attributes included in the operating environment, merge the functions to be monitored corresponding to the at least two monitoring strategies determined, and obtain monitoring indication information.

[0067] Since the client only monitors some functions, in order to avoid monitoring the functions that are attacked by injection, the objects monitored twice are not exactly the same. In one embodiment shown, the call stack information is the call stack information recorded for some functions used to execute the data collection service, and the objects recorded by the call stack information corresponding to two consecutive execution processes of the data collection service are not exactly the same.

[0068] In one illustrated embodiment, the data collection service is used to collect physiological characteristic data required for identity management; the client or server is used to determine that the collected physiological characteristic data is invalid or the identity management result based on the physiological characteristic data is invalid if the identification result indicates that there is an injection risk in the process of executing the data collection service.

[0069] Figure 2 This is a flowchart of a method for identifying injection risks in a data collection process provided by an exemplary embodiment. The execution subject of the method can be an electronic device, a server, or a Figure 1 The system shown. Figure 2 As shown, the method includes step S201 to step S202.

[0070] Step S201 , obtaining call stack information corresponding to a data collection service, wherein the call stack information is call stack information recorded for a function used to execute the data collection service during the execution of the data collection service.

[0071] Among them, the data collection service can be a service that only performs data collection. For example, the data collection service can be a service that collects image data through a camera, or a service that collects sensor data through a sensor. Of course, it can also be a service that collects data through other collection methods, and this specification does not limit this.

[0072] The data collection service may also be a service that not only collects data but also processes the collected data. For example, the data collection service may be a face recognition service that collects face data, identifies whether the collected face data is a complete face, instructs the user to blink, turn the head, etc., and determines whether the user has completed the operation based on the collected face data. For another example, the data collection service may be an iris recognition service that collects iris data and determines whether the collected iris data matches the specified iris data based on the collected iris data. Of course, the data collection service may also be other services that collect data and process the collected data, and this specification does not limit this.

[0073] The number of functions used to execute the data collection service may be one or more. The number of functions may be determined by actual service requirements. This specification does not limit the number of functions used to execute the data collection service.

[0074] The call stack information is a stack structure formed by function calls when the program is executed, which records the calling order and parameters of the functions. The call stack information corresponding to the data collection service is a stack structure formed by function calls when the data collection service is executed, which records the calling order and parameters of the functions used to execute the data collection service.

[0075] Step S202: perform risk identification based on the call stack information to obtain an identification result, which is used to indicate whether there is an injection risk in the process of the data collection business.

[0076] Since the call stack information corresponding to the data collection service records the calling order and parameters of the functions used to execute the data collection service, when an injection attack occurs, the injection attack will leave specific traces in the call stack information. Therefore, analyzing the call stack information can accurately determine whether there is an injection risk.

[0077] In the above technical solution, by recording the call stack information for the function used to execute the data collection business during the execution of the data collection business, it is possible to identify whether there is an injection risk in the process of executing the data collection business. In this way, the identification result can be referred to when performing a series of operations and decisions based on the collected data. This can avoid the injection attack from having a serious impact on the subsequent series of operations and decisions, thereby improving the security of the system.

[0078] Since the call stack information is a stack structure formed by function calls when the program is executed, which records the calling order and parameters of the functions, when an injection attack occurs, the injection attack will leave specific traces in the call stack information. Therefore, analyzing the call stack information can accurately determine whether there is an injection risk.

[0079] In addition, combining the solution provided in this manual with other protection measures against security threats can cover the entire life cycle of data, cope with more complex and changing security environments, and provide users with more secure and reliable security protection.

[0080] It should be noted that the method for identifying injection risks in the data collection process provided in this specification can record call stack information for all functions used to perform data collection services, so that it can more accurately identify whether there is an injection risk; it can also record call stack information for some functions used to perform data collection services, so that it can reduce the amount of calculation and avoid the identification of injection risks affecting the normal operation of the business. Figure 3 The illustrated embodiment exemplarily illustrates a solution for recording call stack information only for a portion of functions used to execute data collection services.

[0081] Figure 3 This is a flowchart of a method for identifying the risk of injection during data collection, which only requires monitoring of some functions, provided by an exemplary embodiment. The execution subject of the method can be an electronic device or Figure 1 The system shown. Figure 3 As shown, the method includes steps S301 to S303.

[0082] Step S301 : Generate monitoring indication information, where the monitoring indication information is determined based on the operating environment of the data collection service, and is used to indicate a function to be monitored, where the function to be monitored includes at least a part of a function used to execute the data collection service.

[0083] In this specification, the function to be monitored indicated by the monitoring indication information is at least a part of the function used to execute the data collection service. When the risk level of the operating environment of the data collection service is very high, the function to be monitored may be all the functions used to execute the data collection service. In other cases, the function to be monitored is a part of the function used to execute the data collection service. In order to reduce the situation where the injection risk is not identified, in this specification, the monitoring indication information will be generated based on the operating environment of the data collection service, so that the monitoring indication information can more accurately indicate the functions that may be attacked by injection, which not only reduces the amount of calculation, but also can more accurately identify whether there is an injection risk.

[0084] Among them, the monitoring indication information is used to indicate the function to be monitored. In some embodiments, the monitoring indication information includes the function name of the function to be monitored. When there are multiple functions to be monitored, the monitoring indication information may include a function name list, and the function name list includes the function names of the multiple functions to be monitored. Of course, the monitoring indication information may also include a function name set, and the function name set includes the function names of the multiple functions to be monitored. This specification only provides an exemplary description of the content of the monitoring indication information and does not limit it. The monitoring indication information may also indicate the function to be monitored in any data form.

[0085] The operating environment of the data collection service may include the software operating environment of the data collection service, or the hardware operating environment of the data collection service, or both the software operating environment and the hardware operating environment, which is not limited in this specification. In some embodiments, the operating environment includes at least one of the current login account, device type, region, and application scenario.

[0086] Among them, the current login account can indicate the software operating environment. The server can determine whether the account is a malicious user based on the historical behavior data of any account. If an account belongs to a malicious user, then the client logged in to the account may be a client that has been attacked by the malicious account. Therefore, based on the current login account, it can be estimated whether the software operating environment of the data collection business is safe.

[0087] The device type can be a device model, such as various models of mobile phones. The device type can also be a type of device, such as mobile phones, tablet computers, wearable devices, etc. Devices of different models or types may run different systems, resulting in different software operating environments for data collection services and different functions that may be injected with attacks. Therefore, based on the device type, the function to be monitored can be determined more accurately, so that the client can still accurately identify injection risks when monitoring some functions.

[0088] In addition, different models of devices or different types of devices have different hardware operating environments, resulting in different data processing capabilities. Therefore, based on the device type, a larger number of functions to be monitored can be determined for devices with high data processing capabilities, and a smaller number of functions to be monitored can be determined for devices with low data processing capabilities.

[0089] In some embodiments, the running versions of the same application in different regions may be different, which results in different functions called by clients in different regions when executing data collection services. Therefore, the functions to be monitored can be determined more accurately based on the region. Of course, in addition to the running versions, different regions may also have other differences, which are not limited in this specification. You only need to refer to the differences brought by different regions to determine the monitoring indication information accordingly.

[0090] The application scenario of the data collection service is the scenario in which the data collection service is applied. The application scenario can be determined by the processing that needs to be done on the collected data. For example, if face recognition needs to be performed on the collected data, then the application scenario can be face recognition. For another example, if the collected data needs to be classified, then the application scenario is classification. Based on the application scenario of the data collection service, the probability of malicious users injecting attacks on the data collection service can be analyzed, and which functions malicious users may inject attacks on can also be analyzed. Therefore, based on the application scenario, the functions to be monitored can be determined more accurately, so that the client can still accurately identify injection risks when monitoring some functions.

[0091] For example, when the data collection service is a face recognition service, an injection attack on the face recognition service may bring huge benefits to malicious users, so the probability of malicious users injecting attacks on the face recognition service is relatively high, and in order to achieve their goals, malicious users may inject attacks on the function of obtaining camera data, or inject attacks on the function of recognizing facial features. Therefore, based on the application scenario, the function of obtaining camera data and the function of recognizing facial features can be determined as the functions to be monitored.

[0092] In one illustrated embodiment, the correspondence between the operating environment and the monitoring strategy is preconfigured. Subsequently, after obtaining the operating environment, the corresponding monitoring strategy can be directly obtained based on the operating environment, and monitoring indication information can be generated based on the monitoring strategy. The monitoring strategy is used to indicate which functions to monitor, or the monitoring strategy is used to indicate how many functions to monitor, or the monitoring strategy is used to indicate how many functions among the specified functions to monitor, wherein the specified function can be a critical function, a function that is susceptible to injection attacks, a function with a high degree of importance, etc. This specification does not limit the specified functions and monitoring strategies.

[0093] In some embodiments, the operating environment includes the current login account, and the correspondence between the operating environment and the monitoring strategy includes the correspondence between the risk level and the monitoring strategy, and the correspondence includes multiple risk levels and the monitoring strategy corresponding to each risk level. The process of generating monitoring indication information includes: obtaining a monitoring strategy that matches the risk level of the current login account from the correspondence between the risk level and the monitoring strategy, determining a function to be monitored based on the monitoring strategy, and generating monitoring indication information based on the determined function to be monitored.

[0094] The risk level of the current login account may be calculated in real time, or obtained from a local memory, or obtained from a memory of another device, for example, from historical data of a server. This specification does not limit this.

[0095] In some embodiments, the operating environment includes a device type, and the correspondence between the operating environment and the monitoring strategy includes a correspondence between the device type and the monitoring strategy. The process of generating the monitoring indication information includes: obtaining a monitoring strategy that matches the device type in the operating environment from the correspondence between the device type and the monitoring strategy, determining a function to be monitored based on the monitoring strategy, and generating the monitoring indication information based on the determined function to be monitored.

[0096] In some embodiments, the operating environment includes the region to which it belongs, and the correspondence between the operating environment and the monitoring strategy includes the correspondence between the region and the monitoring strategy. The process of generating the monitoring indication information includes: obtaining a monitoring strategy matching the region from the correspondence between the region and the monitoring strategy, determining a function to be monitored based on the monitoring strategy, and generating the monitoring indication information based on the determined function to be monitored.

[0097] In some embodiments, the operating environment includes an application scenario, and the correspondence between the operating environment and the monitoring strategy includes the correspondence between the application scenario and the monitoring strategy. The process of generating the monitoring indication information includes: obtaining a monitoring strategy matching the application scenario included in the operating environment from the correspondence between the application scenario and the monitoring strategy, determining a function to be monitored based on the monitoring strategy, and generating the monitoring indication information based on the determined function to be monitored.

[0098] In some embodiments, the operating environment includes at least two environmental attributes of the current login account, device type, region and application scenario, and the process of generating monitoring indication information includes: determining the monitoring strategies corresponding to the at least two environmental attributes based on the at least two environmental attributes included in the operating environment; merging the functions to be monitored corresponding to the at least two monitoring strategies determined to obtain monitoring indication information.

[0099] The correspondence between the operating environment and the monitoring strategy includes the correspondence between at least two environmental attributes and the monitoring strategy. For example, the correspondence between the operating environment and the monitoring strategy includes: the correspondence between the risk level and the monitoring strategy, the correspondence between the equipment type and the monitoring strategy, the correspondence between the region and the monitoring strategy, the correspondence between the application scenario and the monitoring strategy, etc. When determining the monitoring strategies corresponding to the at least two environmental attributes respectively based on the at least two environmental attributes included in the operating environment, the determination can be based on the correspondence between the operating environment and the monitoring strategy.

[0100] For example, the operating environment includes the current login account and the device type. Based on the correspondence between the risk level and the monitoring strategy and the correspondence between the device type and the monitoring strategy, determine the first monitoring strategy corresponding to the risk level of the current login account and the second monitoring strategy corresponding to the device type of the data collection service; determine the function to be monitored corresponding to the first monitoring strategy and the monitoring function corresponding to the second monitoring strategy, take the union of the functions to be monitored corresponding to the two monitoring strategies, and obtain monitoring indication information.

[0101] In some embodiments, the corresponding relationship between the operating environment and the monitoring strategy is not static. In practical applications, injection attacks are constantly improving, so technicians will continuously update the monitoring strategy according to the changes in injection attacks, or continuously update the monitoring strategy based on the changes in injection attacks through a neural network model.

[0102] In another illustrated embodiment, a plurality of monitoring indication information is pre-configured, and appropriate monitoring indication information can be obtained from the pre-configured plurality of monitoring indication information based on the operating environment of the data collection service. The generation process of the monitoring indication information includes: determining the risk level of the data collection service based on the operating environment of the data collection service; and determining the monitoring indication information that matches the risk level from a plurality of alternative monitoring indication information based on the risk level of the data collection service. The risk levels corresponding to the plurality of alternative monitoring indication information are positively correlated with the number of functions to be monitored, that is, the higher the risk level, the more functions need to be monitored.

[0103] Among them, based on the operating environment of the data collection business, the risk level of the data collection business can be determined by calculation through a neural network model, or by the correspondence between the operating environment and the risk level. This specification does not limit how to determine the risk level of the data collection business based on the operating environment of the data collection business.

[0104] Among them, multiple alternative monitoring indication information can be empirical information, can be configured by technical personnel, or can be determined by a neural network model, and this specification does not limit this. In some embodiments, multiple alternative monitoring indication information will give priority to indicating important functions used to perform data collection services. For example, the function to be monitored indicated by the alternative monitoring indication information corresponding to the lowest risk level is the most important function; the function to be monitored indicated by the alternative monitoring indication information corresponding to the second lowest risk level includes the most important function and the second most important function; and so on.

[0105] In another illustrated embodiment, the number of functions to be monitored can be determined based on the operating environment of the data collection service, and the number of functions can be selected from the functions used to perform the data collection service as the functions to be monitored. In some embodiments, in order to ensure that the selected functions have monitoring value, they can be selected from the key functions used to perform the data collection service. Among them, the generation process of monitoring indication information includes: determining the risk level of the data collection service based on the operating environment of the data collection service; determining the number of functions to be monitored based on the risk level of the data collection service, and obtaining the monitoring number, wherein the monitoring number is positively correlated with the risk level; selecting the key functions of the monitoring number from the key functions used to perform the data collection service as the functions to be monitored; and generating monitoring indication information for the data collection service based on the selected functions to be monitored.

[0106] Among them, key functions refer to functions in the application that are crucial to implementing core business logic and ensuring system stability and security. The key functions can be pre-configured locally on the device and directly obtained from the local device when determining the monitoring indication information. Of course, they can also be configured in other devices and obtained from other devices when determining the monitoring indication information.

[0107] Exemplarily, when selecting a number of key functions to be monitored from key functions for executing data collection services, the key functions may be selected randomly or according to certain selection rules, for example, the key function selected this time is not completely the same as the key function selected last time. The term "not completely the same" may be partially the same, partially different, or completely different.

[0108] Since injection attacks usually attack key functions, selecting the functions to be monitored from the key functions makes it easier to monitor the injection attacks, thereby improving the accuracy of injection risk identification.

[0109] It should be noted that this specification only uses the monitoring of some key functions as an example to exemplify the monitoring indication information. In another embodiment, the monitoring indication information indicates the key functions used to execute the data collection service, that is, all key functions of the data collection service are monitored.

[0110] In some embodiments, in order to ensure that the selected function has monitoring value, a function with a higher probability of being attacked can be selected according to the probability of being attacked of the function. The generation process of monitoring indication information includes: determining the risk level of the data collection service based on the operating environment of the data collection service; determining the number of functions to be monitored based on the risk level of the data collection service, and obtaining the monitoring number, wherein the monitoring number is positively correlated with the risk level; selecting the functions with the monitoring number from the functions used to execute the data collection service in the order of the probability of being attacked from high to low as the functions to be monitored; and generating monitoring indication information of the data collection service based on the selected functions to be monitored.

[0111] Among them, the functions used to execute data collection services are arranged in order from high to low according to the probability of being attacked. They can be empirical values, configured by technical personnel, or determined by a neural network model, and this manual does not limit this.

[0112] Exemplarily, when selecting a monitored number of functions from the functions used to perform data collection services as the functions to be monitored in descending order of attack probability, the functions may be selected randomly or according to certain selection rules, for example, the function selected this time is not completely the same as the function selected last time. The term "not completely the same" may mean partially the same, partially different, or completely different.

[0113] Since the above method for generating monitoring indication information will give priority to monitoring functions with a high probability of being attacked, it is possible to more accurately determine the functions to be monitored, so that the client can still accurately identify injection risks when monitoring some functions.

[0114] In other embodiments, in order to ensure that the selected functions have monitoring value, important functions can be selected according to the importance of the functions. The generation process of monitoring indication information includes: determining the risk level of the data collection service based on the operating environment of the data collection service; determining the number of functions to be monitored based on the risk level of the data collection service, and obtaining the monitoring number, wherein the monitoring number is positively correlated with the risk level; selecting the functions with the monitoring number from the functions used to execute the data collection service in order of importance from high to low as the functions to be monitored; and generating monitoring indication information of the data collection service based on the selected functions to be monitored.

[0115] Among them, the functions used to execute data collection services are arranged in order from high to low in terms of importance. They can be empirical values, configured by technical personnel, or determined by a neural network model, and this specification does not limit this.

[0116] Exemplarily, when selecting the functions of the monitored quantity from the functions used to perform the data collection business in descending order of importance as the functions to be monitored, the functions may be selected randomly or according to certain selection rules, for example, the function selected this time is not completely the same as the function selected last time. The not completely the same may be partially the same, partially different, or completely different.

[0117] Since the consequences of injection attacks on functions with higher importance are more serious, the above method of generating monitoring indication information will give priority to monitoring functions with higher importance. If an injection attack is carried out on a function with higher importance, some attack traces of the injection attack will be recorded in the call stack information during the running of the function. Subsequently, it can be identified whether a function with higher importance has been subjected to an injection attack. A series of subsequent operations and decisions can be executed based on the identification results, thereby avoiding the serious consequences of injection attacks on functions with higher importance and improving the security of the system.

[0118] In one illustrated embodiment, the call stack information is the call stack information recorded for some functions used to execute data collection services. In order to monitor the data collection service more flexibly, the monitoring objects of two adjacent monitoring processes may be different, that is, the recording objects targeted by the call stack information corresponding to two adjacent execution processes of the data collection service are not completely the same. Among them, the recording object is the function used to execute the data collection service. Exemplarily, after determining the function to be monitored in this monitoring process, the monitoring indication information of the previous monitoring process is obtained, and based on the monitoring indication information of the previous monitoring process, the function to be monitored in this monitoring process is updated, so that the function to be monitored in this monitoring process is not completely the same as the function to be monitored in the previous monitoring process, and the monitoring indication information of this monitoring process is generated based on the function to be monitored in this monitoring process.

[0119] It should be noted that this specification only takes the example of determining the monitoring indication information based on the operating environment of the data collection service to exemplify the process of determining the monitoring indication information. In another embodiment, the function to be monitored indicated by the monitoring indication information is a key function for executing the data collection service, that is, in the process of executing the data collection service, the call stack information is recorded for all key functions used to execute the data collection service. In another embodiment, the function to be monitored indicated by the monitoring indication information can be determined randomly or based on other information, and this specification does not limit this.

[0120] Exemplarily, if the monitoring function indicated by the monitoring indication information is randomly determined, the functions to be monitored indicated by two adjacent monitoring indication information are not exactly the same, that is, the recording objects targeted by the call stack information corresponding to two adjacent execution processes of the data collection service are not exactly the same.

[0121] Step S302: in the process of executing the data collection service, based on the monitoring indication information, recording the call stack information for each function to be monitored.

[0122] Since the function to be monitored indicated by the monitoring indication information may be a partial function for executing the data collection service, the aspect component (Aspect) may be used to generate the call stack information of the partial function during implementation. Exemplarily, since the aspect component may define how and when to apply a specific behavior to a target object, the aspect component may define the recording of the call stack information of the function to be monitored when the data collection service is executed. After the data collection service is started, the aspect component may obtain the monitoring indication information, determine the function to be monitored based on the monitoring indication information, and record the call stack information of the function to be monitored.

[0123] Step S303: perform risk identification based on the call stack information to obtain an identification result, which is used to indicate whether there is an injection risk in the process of executing the data collection business.

[0124] Since the call stack information corresponding to the data collection service records the calling order and parameters of the functions used to execute the data collection service, when an injection attack occurs, the injection attack will leave specific traces in the call stack information. Therefore, analyzing the call stack information can accurately determine whether there is an injection risk.

[0125] In an illustrated embodiment, risk identification is performed based on call stack information to obtain an identification result, including: for the call stack information of each function to be monitored, the abnormal characteristics of each function to be monitored are respectively obtained, and whether the corresponding abnormal characteristics exist in the call stack information of each function to be monitored; if the corresponding abnormal characteristics exist in the call stack information of any function to be monitored, a first identification result is generated, and the first identification result is used to indicate that there is an injection risk in the process of executing the data collection business; if the call stack information of each function to be monitored does not include the corresponding abnormal characteristics, a second identification result is generated, and the second identification result is used to indicate that there is no injection risk in the process of executing the data collection business.

[0126] Among them, the abnormal feature can be an abnormal value, an abnormal field of a certain type, or a feature vector extracted by a neural network model. This specification does not limit the abnormal feature.

[0127] In some embodiments, in order to more accurately identify risks in the call stack information, the abnormal features are continuously updated. Among them, the abnormal features can be updated by technicians or automatically. For example, the server can obtain the call stack information of multiple clients, perform feature aggregation processing on the call stack information of multiple clients, determine discrete features, and use the discrete features as abnormal features. In this way, when a new injection attack occurs, it can be discovered in time, further improving the security of the system.

[0128] It should be noted that after obtaining the recognition result, the next operation or decision can be made based on the recognition result. Taking the identity management scenario as an example, the data collection service is used to collect physiological characteristic data required for identity management. The method also includes: if the recognition result indicates that there is an injection risk in the process of executing the data collection service, it is determined that the collected physiological characteristic data is invalid or the identity management result based on the physiological characteristic data is invalid.

[0129] Among them, identity management can be identity recognition, for example, identifying whether the current user is the target user; it can also be identity registration, for example, registering an account for the current user; it can also be identity authorization, for example, authorizing which resources the user can access and which operations can be performed on these resources, etc. For example, an authorized user can use the resources in the corresponding account, and this specification does not limit identity management.

[0130] When the identification results indicate that there is an injection risk in the process of executing the data collection business, the collected physiological characteristic data may be tampered with, and identity management based on the collected physiological characteristic data may have a serious impact on the user's information security or property security. Therefore, the collected physiological characteristic data is judged to be invalid, so that identity management cannot be performed based on the physiological characteristic data. Alternatively, the identity management result based on the physiological characteristic data is judged to be invalid, thereby avoiding the tampered physiological characteristic data from having a serious impact on the user's information security or property security, and improving the security of the system.

[0131] Next, this specification takes the face recognition business as an example to illustrate the method of injecting risks in the recognition data collection process:

[0132] like Figure 4As shown, the user starts face recognition on the client, and the client executes the face recognition service to collect face images. In the process of collecting face images, the call stack information is recorded for the key functions used to execute the face recognition service. In addition, the face recognition service will also process the collected face images, for example, to identify whether the collected face images include a complete face. If the collected face images do not include a complete face, the user is prompted to move so that the client can collect the complete face. For example, the face recognition service can prompt the user to complete operations such as blinking and turning the head, and determine whether the user has completed operations such as blinking and turning the head based on the collected face images. Therefore, the key functions used to execute the face recognition service include not only functions for obtaining camera data, but also functions for facial feature recognition.

[0133] The client uploads the recorded call stack information to the server, which identifies the call stack information to determine whether abnormal features are detected. If abnormal features are detected, it is determined that there is an injection risk, and the client is denied further access based on the face recognition results, and the corresponding log is recorded. If no abnormal features are detected, the client is authorized to access further based on the face recognition results.

[0134] In the above technical solution, by recording the call stack information for the function used to execute the data collection business during the execution of the data collection business, it is possible to identify whether there is an injection risk in the process of executing the data collection business. In this way, the identification result can be referred to when performing a series of operations and decisions based on the collected data. This can avoid the injection attack from having a serious impact on the subsequent series of operations and decisions, thereby improving the security of the system.

[0135] Since the call stack information is a stack structure formed by function calls when the program is executed, which records the calling order and parameters of the functions, when an injection attack occurs, the injection attack will leave specific traces in the call stack information. Therefore, analyzing the call stack information can accurately determine whether there is an injection risk.

[0136] In addition, combining the solution provided in this manual with other protection measures against security threats can cover the entire life cycle of data, cope with more complex and changing security environments, and provide users with more secure and reliable security protection.

[0137] Figure 5 is a flowchart of a method for identifying injection risks in a data collection process provided by an exemplary embodiment. The execution subject of the method may be Figure 1 The system shown. Figure 5 As shown, the method includes step S501 to step S502.

[0138] Step S501 : during the process of executing the data collection service, the client records the call stack information for the function used to execute the data collection service, and sends the call stack information to the server.

[0139] In an illustrated implementation, during the process of executing the data collection service, the client records call stack information for all functions used to execute the data collection service.

[0140] In another illustrated embodiment, the client records call stack information for some functions used to execute the data collection service during the execution of the data collection service.

[0141] In some embodiments, the client records call stack information for some functions used to execute the data collection service during the execution of the data collection service, including: the client records call stack information for key functions used to execute the data collection service during the execution of the data collection service. In another embodiment, the client records call stack information for each function to be monitored based on monitoring indication information during the execution of the data collection service.

[0142] The monitoring indication information may be generated by the client or obtained from the server. The generation process of the monitoring indication information may refer to the above step S301, which will not be described in detail here, and only the interactive mode of the client obtaining the monitoring indication information from the server is exemplified.

[0143] In some embodiments, the method also includes: the client sends a monitoring indication acquisition request to the server in response to a start instruction of the data collection service, and the monitoring indication acquisition request is used to indicate the operating environment of the data collection service; the server receives the monitoring indication acquisition request, generates monitoring indication information based on the operating environment of the data collection service, and returns the monitoring indication information to the client based on the monitoring indication acquisition request; the client receives the monitoring indication information, and in the process of executing the data collection service, records the call stack information for each function to be monitored based on the monitoring indication information.

[0144] Step S502: The server receives call stack information, performs risk identification based on the call stack information, and obtains an identification result, which is used to indicate whether there is an injection risk in the process of executing the data collection business.

[0145] Among them, the above step S502 is similar to the above step S303, and can refer to the above step S303, which will not be repeated here.

[0146] After obtaining the recognition result, the server can perform the next operation or decision based on the recognition result; or, send the recognition result to the client so that the client can perform the next operation or decision based on the recognition result. The specific situation can be configured according to business needs, and this manual does not limit this.

[0147] It should be noted that this manual is only Figure 5 Taking the embodiment shown as an example, the cooperation between the client and the server to complete the risk injection method in the process of identifying data collection is exemplified, and no limitation is imposed on which specific steps are performed by the client and the server in the process of the client and the server cooperating to complete the method. In another embodiment, the client performs risk identification based on the call stack information, obtains an identification result, and sends the identification result to the server, or sends the collected data and the identification result to the server.

[0148] In the above technical solution, by recording the call stack information for the function used to execute the data collection business during the execution of the data collection business, it is possible to identify whether there is an injection risk in the process of executing the data collection business. In this way, the identification result can be referred to when performing a series of operations and decisions based on the collected data. This can avoid the injection attack from having a serious impact on the subsequent series of operations and decisions, thereby improving the security of the system.

[0149] Since the call stack information is a stack structure formed by function calls when the program is executed, which records the calling order and parameters of the functions, when an injection attack occurs, the injection attack will leave specific traces in the call stack information. Therefore, analyzing the call stack information can accurately determine whether there is an injection risk.

[0150] In addition, combining the solution provided in this manual with other protection measures against security threats can cover the entire life cycle of data, cope with more complex and changing security environments, and provide users with more secure and reliable security protection.

[0151] Figure 6 is a schematic structural diagram of a device provided by an exemplary embodiment. Figure 6At the hardware level, the device includes a processor 602, an internal bus 604, a network interface 606, a memory 608, and a non-volatile memory 610, and may also include hardware required for other functions. One or more embodiments of this specification may be implemented based on software, such as the processor 602 reading the corresponding computer program from the non-volatile memory 610 into the memory 608 and then running it. Of course, in addition to the software implementation, one or more embodiments of this specification do not exclude other implementations, such as logic devices or a combination of software and hardware, etc., that is, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.

[0152] Please refer to Figure 7 ,The device for identifying the risk of injection during data collection can be applied to e.g. Figure 6 The device shown in the figure can realize the technical solution of this specification. Among them, the device for identifying the risk of injection during data collection can include:

[0153] The acquisition unit 701 is used to acquire call stack information corresponding to the data collection service, where the call stack information is call stack information recorded for the function used to execute the data collection service during the execution of the data collection service;

[0154] The identification unit 702 is used to perform risk identification based on the call stack information to obtain an identification result, and the identification result is used to indicate whether there is an injection risk in the process of executing the data collection business.

[0155] In one illustrated embodiment, the call stack information includes call stack information of the function to be monitored indicated by the monitoring indication information, and the monitoring indication information is determined based on the operating environment of the data collection service; wherein the function to be monitored includes at least a portion of the function used to execute the data collection service.

[0156] In an illustrated embodiment, the process of generating monitoring indication information includes:

[0157] Determine the risk level of the data collection business based on the operating environment of the data collection business;

[0158] Based on the risk level of the data collection service, monitoring indication information matching the risk level is determined from a plurality of candidate monitoring indication information, and the risk levels corresponding to the plurality of candidate monitoring indication information are positively correlated with the number of indicated functions to be monitored.

[0159] In an illustrated embodiment, the process of generating monitoring indication information includes:

[0160] Determine the risk level of the data collection business based on the operating environment of the data collection business;

[0161] Based on the risk level of the data collection business, determine the number of functions that need to be monitored and obtain the monitoring quantity, which is positively correlated with the risk level;

[0162] From the key functions for executing data collection services, select the key functions that monitor the number of functions as the functions to be monitored; or, in descending order of attack probability, select the functions that monitor the number of functions from the functions for executing data collection services as the functions to be monitored; or, in descending order of importance, select the functions that monitor the number of functions from the functions for executing data collection services as the functions to be monitored;

[0163] Based on the selected function to be monitored, monitoring indication information of the data collection service is generated.

[0164] In an illustrated embodiment, the operating environment includes at least two environmental attributes of the current login account, device type, region, and application scenario; and the generation process of the monitoring indication information includes:

[0165] Based on at least two environmental attributes included in the operating environment, determining monitoring strategies corresponding to the at least two environmental attributes respectively;

[0166] The functions to be monitored corresponding to the at least two determined monitoring strategies are merged to obtain monitoring indication information.

[0167] In an illustrated embodiment, the call stack information is the call stack information recorded for a portion of functions used to execute the data collection service, and the record objects targeted by the call stack information corresponding to two adjacent execution processes of the data collection service are not completely the same.

[0168] In one illustrated embodiment, the data collection service is used to collect physiological characteristic data required for identity management, and the device also includes: a determination unit, which is used to determine that the collected physiological characteristic data is invalid or the identity management result based on the physiological characteristic data is invalid if the identification result indicates that there is an injection risk in the process of executing the data collection service.

[0169] Based on the same concept as the above method, this specification also provides an electronic device, including: a processor; a memory for storing processor executable instructions; wherein the processor implements the steps of the method described in any of the above embodiments by running the executable instructions.

[0170] Based on the same concept as the above method, this specification also provides a computer-readable storage medium on which computer instructions are stored. When the instructions are executed by a processor, the steps of the method described in any of the above embodiments are implemented.

[0171] Based on the same concept as the above method, this specification also provides a computer program product, including a computer program / instruction, which implements the steps of the method described in any of the above embodiments when executed by a processor.

Claims

1. A method for identifying injection risks in a data collection process, the method comprising: Acquire call stack information corresponding to the data collection service, wherein the call stack information is call stack information recorded for a function used to execute the data collection service during the execution of the data collection service; Risk identification is performed based on the call stack information to obtain an identification result, and the identification result is used to indicate whether there is an injection risk in the process of executing the data collection business.

2. According to the method of claim 1, the call stack information includes the call stack information of the function to be monitored indicated by the monitoring indication information, and the monitoring indication information is determined based on the operating environment of the data collection service; wherein, The function to be monitored includes at least a part of the function used to execute the data collection service.

3. According to the method of claim 2, the process of generating the monitoring indication information comprises: Determining a risk level of the data collection service based on the operating environment of the data collection service; Based on the risk level of the data collection service, monitoring indication information matching the risk level is determined from a plurality of candidate monitoring indication information, wherein the risk levels corresponding to the plurality of candidate monitoring indication information are positively correlated with the number of indicated functions to be monitored.

4. According to the method of claim 2, the process of generating the monitoring indication information comprises: Determining a risk level of the data collection service based on the operating environment of the data collection service; Based on the risk level of the data collection service, the number of functions to be monitored is determined to obtain a monitoring number, where the monitoring number is positively correlated with the risk level; Selecting the monitored number of key functions as the functions to be monitored from the key functions used to perform the data collection service; or, in descending order of attack probability, selecting the monitored number of functions as the functions to be monitored from the functions used to perform the data collection service; or, in descending order of importance, selecting the monitored number of functions as the functions to be monitored from the functions used to perform the data collection service; Based on the selected function to be monitored, monitoring indication information of the data collection service is generated.

5. The method according to claim 2, wherein the operating environment includes at least two environmental attributes of the current login account, device type, region, and application scenario; The generation process of the monitoring indication information includes: Based on at least two environmental attributes included in the operating environment, determining monitoring strategies corresponding to the at least two environmental attributes respectively; The functions to be monitored corresponding to the at least two determined monitoring strategies are merged to obtain the monitoring indication information.

6. According to the method described in claim 1, the call stack information is the call stack information recorded for some functions used to execute the data collection service, and the record objects targeted by the call stack information corresponding to two adjacent execution processes of the data collection service are not completely the same.

7. The method according to claim 1, wherein the data collection service is used to collect physiological characteristic data required for identity management, and the method further comprises: If the identification result indicates that there is an injection risk in the process of executing the data collection service, it is determined that the collected physiological characteristic data is invalid or the identity management result made based on the physiological characteristic data is invalid.

8. A system for identifying injection risks during data collection, the system comprising a client and a server; The client is used to record call stack information for a function used to execute the data acquisition service during the execution of the data acquisition service, and send the call stack information to the server; The server is used to receive the call stack information, perform risk identification based on the call stack information, and obtain an identification result, wherein the identification result is used to indicate whether there is an injection risk in the process of executing the data collection business.

9. An electronic device, comprising: processor; A memory for storing processor-executable instructions; wherein the processor implements the steps of the method according to any one of claims 1 to 7 by executing the executable instructions.

10. A computer-readable storage medium having computer instructions stored thereon, wherein the instructions, when executed by a processor, implement the steps of the method according to any one of claims 1 to 7.

Citation Information

Cited By

  • Identification of injection risk during data acquisition

    WO2026157389A1