Privacy compliance detection method and device, electronic equipment and storage medium
By acquiring the collection of detection nodes and determining the life cycle nodes of the target application, and formulating detection strategies based on these nodes, the problem that existing privacy compliance detection tools cannot be applied to multiple scenarios is solved, and comprehensive privacy compliance detection is achieved during the application life cycle, improving the accuracy and real-time detection.
Patent Information
- Application Number
- CN202311526936.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-15
- Publication Date
- 2025-05-23
AI Technical Summary
The existing privacy compliance inspection tools are only suitable for offline privacy compliance inspection of APPs, and cannot be used for privacy compliance inspection in other scenarios, such as online privacy compliance inspection of APPs, privacy compliance inspection during local development of APPs, privacy compliance inspection during APP code changes, etc.
Provide a privacy compliance detection method, by obtaining a collection of detection nodes, determining nodes in the life cycle of the target application, determining detection policies based on these nodes, and performing privacy compliance detection. This method includes detecting different life cycle nodes such as application development, code editing, online and offline nodes, and using technical means such as integrated development environment plug-ins, decompilation tools, and bytecode operation frameworks.
It realizes privacy compliance detection during the application life cycle, and can prompt R&D personnel for real-time calls to the privacy API, reduces the risk of privacy compliance problems, and improves the comprehensiveness and accuracy of detection.
Smart Images

Figure CN120029875A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a privacy compliance detection method, device, electronic device and storage medium. Background Art
[0002] With the popularity of smart phones, the number of mobile Internet applications (Application, APP for short) is increasing. Although various APPs can bring a lot of convenience to people's lives, there are some APPs that illegally collect user privacy data outside of their main business needs.
[0003] Therefore, the existing privacy compliance detection tools can realize offline privacy compliance detection of APP. However, these privacy compliance detection tools have certain limitations. They are only applicable to offline privacy compliance detection of APP, but not to privacy compliance detection in other scenarios, such as online privacy compliance detection of APP, privacy compliance detection during local development of APP, privacy compliance detection during APP code modification, etc. Summary of the invention
[0004] In order to solve the technical problems that the above-mentioned privacy compliance detection tools have certain limitations and are only applicable to offline privacy compliance detection of APPs, but not applicable to privacy compliance detection in other scenarios, such as online privacy compliance detection of APPs, privacy compliance detection during local development of APPs, and privacy compliance detection during APP code modification, the embodiments of this application provide a privacy compliance detection method, device, electronic device, and storage medium. The specific technical solutions are as follows:
[0005] In a first aspect of an embodiment of the present application, a privacy compliance detection method is first provided, the method comprising:
[0006] Get the detection node set;
[0007] Determine a target application, wherein the detection nodes in the detection node set correspond one-to-one to the nodes in the life cycle of the target application;
[0008] A detection strategy is determined based on the node, and the privacy compliance of the target application is detected according to the detection strategy.
[0009] In an optional implementation, determining a detection strategy based on the node, and detecting the privacy compliance of the target application according to the detection strategy includes:
[0010] In the case where the life cycle runs to a target node in the node, determining a target detection node corresponding to the target node;
[0011] The privacy compliance of the target application is detected using the detection strategy associated with the target detection node.
[0012] In an optional implementation, when the life cycle runs to a target node in the node, determining a target detection node corresponding to the target node includes:
[0013] When the life cycle runs to an application development node in the nodes, an application development detection node corresponding to the application development node is determined.
[0014] In an optional implementation, the detecting the privacy compliance of the target application using the detection strategy associated with the target detection node includes:
[0015] Find the integrated development environment plug-in associated with the application development detection node, and call the integrated development environment plug-in to perform the following detection operations:
[0016] Obtaining current code in an application development file of the target application, and detecting whether there is a call to a privacy application programming interface in the current code;
[0017] In the event of a call, the privacy application programming interface in the current code is marked.
[0018] In an optional implementation, the detecting whether there is a call to a privacy application programming interface in the current code includes:
[0019] Get privacy API data;
[0020] Traversing the application programming interface in the current code, and determining whether the application programming interface matches the privacy application programming interface in the privacy application programming interface data;
[0021] In the case of a match, determining that a call to the privacy application programming interface exists in the current code;
[0022] If there is no match, it is determined that there is no call to the privacy application programming interface in the current code.
[0023] In an optional implementation, when the life cycle runs to a target node in the node, determining a target detection node corresponding to the target node includes:
[0024] When the life cycle runs to an offline node in the nodes, an offline detection node corresponding to the offline node is determined.
[0025] In an optional implementation, the detecting the privacy compliance of the target application using the detection strategy associated with the target detection node includes:
[0026] When the target detection node is an offline detection node, perform the following privacy compliance detection operation;
[0027] Decompiling the target application program's files to obtain class files and manifest files;
[0028] Obtaining the bytecode content in the class file and the file content of the manifest file;
[0029] Determining whether there is a call to a privacy application programming interface in the bytecode content and the file content;
[0030] If there is a call, the privacy application programming interface is displayed and saved in the privacy compliance detection report.
[0031] In an optional implementation, after obtaining the bytecode content in the class file and the file content of the manifest file, the method further includes:
[0032] Determine whether there is a definition of high-risk permissions in the bytecode content and the file content;
[0033] In the case where a definition of the high-risk permission exists, the definition of the high-risk permission is displayed and saved in the privacy compliance detection report.
[0034] In an optional embodiment, the method further comprises:
[0035] When the life cycle runs to the application self-starting node in the node, the following application self-starting detection operation is performed:
[0036] Capturing the running log of the target application, and filtering the target running log related to the application self-starting from the running log;
[0037] The target operation log is displayed, and the target operation log is marked according to the level of the target operation log.
[0038] In an optional implementation, when the life cycle runs to a target node in the node, determining a target detection node corresponding to the target node includes:
[0039] When the life cycle runs to a code editing node in the node, a code editing detection node corresponding to the code editing node is determined.
[0040] In an optional implementation, the detecting the privacy compliance of the target application using the detection strategy associated with the target detection node includes:
[0041] Find the task corresponding to the code editing detection node, and perform the following privacy compliance detection operations through the task when a code merge request is triggered:
[0042] Determine the file where code editing occurs in the target application, and the code line number where code editing occurs;
[0043] The files where the code editing occurs and the code line numbers where the code editing occurs are saved in the detection set;
[0044] Detecting whether there is a call to a privacy application programming interface in the detection set;
[0045] If there is a call, the file and code line number that call the privacy application programming interface are output in the privacy compliance detection report.
[0046] In an optional implementation, when the life cycle runs to a target node in the node, determining a target detection node corresponding to the target node includes:
[0047] When the life cycle runs to an online node in the nodes, an online detection node corresponding to the online node is determined.
[0048] In an optional implementation, the detecting the privacy compliance of the target application using the detection strategy associated with the target detection node includes:
[0049] Find the first parsing tool and the second parsing tool corresponding to the online detection node, and perform the following privacy compliance detection operations;
[0050] Parsing the class file of the target application program through the first parsing tool to obtain a pre-configured tool class;
[0051] Parsing the remaining class files of the target application using the second parsing tool to obtain parsing results;
[0052] Analyzing whether there is a call to a privacy application programming interface in the parsing result;
[0053] If there is a call, determining the call bytecode instruction corresponding to the privacy application programming interface;
[0054] Replacing the calling bytecode instruction with the corresponding bytecode instruction in the tool class;
[0055] The target application is recompiled to obtain data of the target application.
[0056] In a second aspect of the embodiments of the present application, a privacy compliance detection device is further provided, the device comprising:
[0057] A collection acquisition module is used to acquire a detection node collection;
[0058] A program determination module, used to determine a target application, wherein the detection nodes in the detection node set correspond one-to-one to the nodes in the life cycle of the target application;
[0059] A privacy compliance detection module is used to determine a detection strategy based on the node, and detect the privacy compliance of the target application according to the detection strategy.
[0060] In an optional implementation, the privacy compliance detection module specifically includes:
[0061] A node determination submodule, used for determining a target detection node corresponding to the target node when the life cycle runs to the target node in the node;
[0062] The privacy compliance detection submodule is used to detect the privacy compliance of the target application using the detection strategy associated with the target detection node.
[0063] In an optional implementation, the node determination submodule is specifically used to:
[0064] When the life cycle runs to an application development node in the nodes, an application development detection node corresponding to the application development node is determined.
[0065] In an optional implementation, the privacy compliance detection submodule specifically includes:
[0066] A plug-in search unit, used to search for an integrated development environment plug-in associated with the application development detection node;
[0067] The plug-in calling unit is used to call the integrated development environment plug-in to perform the following detection operations:
[0068] A code acquisition unit, used to acquire the current code in the application development file of the target application;
[0069] A code detection unit, used to detect whether there is a call to a privacy application programming interface in the current code;
[0070] An interface marking unit is used to mark the privacy application programming interface in the current code when there is a call.
[0071] In an optional implementation, the code detection unit is specifically used to:
[0072] Get privacy API data;
[0073] Traversing the application programming interface in the current code, and determining whether the application programming interface matches the privacy application programming interface in the privacy application programming interface data;
[0074] In the case of a match, determining that a call to the privacy application programming interface exists in the current code;
[0075] If there is no match, it is determined that there is no call to the privacy application programming interface in the current code.
[0076] In an optional implementation, the node determination submodule is specifically used to:
[0077] When the life cycle runs to an offline node in the nodes, an offline detection node corresponding to the offline node is determined.
[0078] In an optional implementation, the privacy compliance detection submodule is specifically used to:
[0079] When the target detection node is an offline detection node, perform the following privacy compliance detection operation;
[0080] Decompiling the target application program's files to obtain class files and manifest files;
[0081] Obtaining the bytecode content in the class file and the file content of the manifest file;
[0082] Determining whether there is a call to a privacy application programming interface in the bytecode content and the file content;
[0083] If there is a call, the privacy application programming interface is displayed and saved in the privacy compliance detection report.
[0084] In an optional implementation, the privacy compliance detection module is further used to:
[0085] Determine whether there is a definition of high-risk permissions in the bytecode content and the file content;
[0086] In the case where a definition of the high-risk permissions exists, the definition of the high-risk permissions is displayed and saved in the privacy compliance detection report.
[0087] In an optional embodiment, the device further comprises:
[0088] The self-start detection module is used to perform the following application self-start detection operations when the life cycle runs to the application self-start node in the node:
[0089] Capturing the running log of the target application, and filtering the target running log related to the application self-starting from the running log;
[0090] The target operation log is displayed, and the target operation log is marked according to the level of the target operation log.
[0091] In an optional implementation, the node determination submodule is specifically used to:
[0092] When the life cycle runs to a code editing node in the node, a code editing detection node corresponding to the code editing node is determined.
[0093] In an optional implementation, the privacy compliance detection submodule is specifically used to:
[0094] Find the task corresponding to the code editing detection node, and perform the following privacy compliance detection operations through the task when a code merge request is triggered:
[0095] Determine the file where code editing occurs in the target application, and the code line number where code editing occurs;
[0096] The files where the code editing occurs and the code line numbers where the code editing occurs are saved in the detection set;
[0097] Detecting whether there is a call to a privacy application programming interface in the detection set;
[0098] If there is a call, the file and code line number that call the privacy application programming interface are output in the privacy compliance detection report.
[0099] In an optional implementation, the node determination submodule is specifically used to:
[0100] When the life cycle runs to an online node in the nodes, an online detection node corresponding to the online node is determined.
[0101] In an optional implementation, the privacy compliance detection submodule is specifically used to:
[0102] Find the first parsing tool and the second parsing tool corresponding to the online detection node, and perform the following privacy compliance detection operations;
[0103] Parsing the class file of the target application program through the first parsing tool to obtain a pre-configured tool class;
[0104] Parsing the remaining class files of the target application using the second parsing tool to obtain parsing results;
[0105] Analyzing whether there is a call to a privacy application programming interface in the parsing result;
[0106] If there is a call, determining the call bytecode instruction corresponding to the privacy application programming interface;
[0107] Replacing the calling bytecode instruction with the corresponding bytecode instruction in the tool class;
[0108] The target application is recompiled to obtain data of the target application.
[0109] In a third aspect of the embodiments of the present application, there is further provided an electronic device, comprising a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus;
[0110] Memory, used to store computer programs;
[0111] The processor is used to implement any privacy compliance detection method described in the first aspect when executing a program stored in the memory.
[0112] In a fourth aspect of an embodiment of the present application, a storage medium is further provided, wherein instructions are stored in the storage medium, and when the storage medium is run on a computer, the computer executes any privacy compliance detection method described in the first aspect above.
[0113] In a fifth aspect of an embodiment of the present application, a computer program product comprising instructions is also provided, which, when executed on a computer, enables the computer to execute any of the privacy compliance detection methods described above.
[0114] The technical solution provided in the embodiment of the present application obtains a detection node set, determines a target application, the detection nodes in the detection node set correspond one-to-one to the nodes in the life cycle of the target application, determines a detection strategy based on the nodes, and detects the privacy compliance of the target application according to the detection strategy. By obtaining a detection node set and determining a target application, determining a detection strategy based on the nodes, and detecting the privacy compliance of the target application according to the detection strategy, privacy compliance detection within the life cycle of the application can be achieved. BRIEF DESCRIPTION OF THE DRAWINGS
[0115] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0116] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0117] One or more embodiments are exemplarily described by pictures in the corresponding drawings, and these exemplified descriptions do not constitute limitations on the embodiments. Elements with the same reference numerals in the drawings represent similar elements, and unless otherwise stated, the figures in the drawings do not constitute proportional limitations.
[0118] Figure 1 A schematic diagram of an implementation process of a privacy compliance detection method shown in an embodiment of the present application;
[0119] Figure 2 This is a schematic diagram of an implementation process of another privacy compliance detection method shown in an embodiment of the present application;
[0120] Figure 3 This is a schematic diagram of an implementation process of another privacy compliance detection method shown in an embodiment of the present application;
[0121] Figure 4 This is a schematic diagram of an implementation process of another privacy compliance detection method shown in an embodiment of the present application;
[0122] Figure 5 This is a schematic diagram of an implementation process of another privacy compliance detection method shown in an embodiment of the present application;
[0123] Figure 6 A schematic diagram of the structure of a privacy compliance detection device shown in an embodiment of the present application;
[0124] Figure 7 It is a schematic diagram of the structure of an electronic device shown in an embodiment of the present application. DETAILED DESCRIPTION
[0125] In order to make the purpose, technical solution and advantages of the embodiments of the present application clearer, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.
[0126] The disclosure below provides many different embodiments or examples to realize the different structures of the present application. In order to simplify the disclosure of the present application, the parts and settings of specific examples are described below. Of course, they are only examples, and the purpose is not to limit the present application. In addition, the present application can repeat reference numbers and / or letters in different examples. This repetition is for the purpose of simplification and clarity, and does not itself indicate the relationship between the various embodiments and / or settings discussed.
[0127] In the embodiments of the present application, the scenarios for privacy compliance testing of applications may generally include offline privacy compliance testing based on the permissions set by R&D personnel, privacy compliance testing for application development (i.e., local development), online privacy compliance testing, and privacy compliance testing for code editing (i.e., code modification). These scenarios run through the life cycle of the application, and the content tested is compliant and the testing methods are legal. For example, privacy compliance testing for application development corresponds to the application development node in the life cycle of the application.
[0128] To this end, in order to achieve privacy compliance testing within the life cycle of the application, it is no longer limited to offline privacy compliance testing. For each node in the life cycle of the application, a detection node can be set, and the detection node has a corresponding detection mechanism. Therefore, when the life cycle of the target application runs to the target node, the detection mechanism of the target detection node associated with the target node can be used to detect the privacy compliance of the target application; among them, the nodes in the life cycle of the application are set according to user needs.
[0129] Based on this, Figure 1 FIG. 1 is a schematic diagram of an implementation process of a privacy compliance detection method provided in an embodiment of the present application. The method is applied to an electronic device and may specifically include the following steps:
[0130] S101, obtaining a detection node set.
[0131] In an embodiment of the present application, a detection node set can be obtained, wherein the detection node set includes multiple detection nodes, each detection node corresponds to a corresponding node in the life cycle of the application, meaning that the detection nodes in the detection node set correspond one-to-one to the nodes in the life cycle of the target application.
[0132] For the detection node, for example, it can be an application development detection node, which means that when developers develop applications locally, they need to perform privacy compliance detection on the applications, specifically, to detect the calls to the privacy API in the developed application code.
[0133] For the detection node, for example, it can be a code editing detection node, which means that when the developer edits (for example, changes) the code, it is necessary to perform privacy compliance detection on the application, specifically to detect the call of the privacy API in the modified application code.
[0134] For detection nodes, for example, they can be online detection nodes, which means that when developers launch applications, they need to perform privacy compliance detection on the applications, specifically detecting the calls to the privacy APIs in the applications.
[0135] S102, determining a target application, wherein the detection nodes in the detection node set correspond one-to-one to the nodes in the life cycle of the target application.
[0136] In an embodiment of the present application, an application that needs to undergo privacy compliance testing throughout its life cycle can be determined, namely, a target application, where the detection nodes in the above detection node set correspond one-to-one to the nodes in the life cycle of the target application.
[0137] For example, determine the target APP, which needs to undergo privacy compliance testing throughout its life cycle. The application development detection node in the above detection node set corresponds to the application development node in the life cycle of the target APP, the code editing detection node corresponds to the code editing node in the life cycle of the target APP, and so on.
[0138] S103, determining a detection strategy based on the node, and detecting the privacy compliance of the target application according to the detection strategy.
[0139] In an embodiment of the present application, for a node in the life cycle of a target application, a detection strategy can be determined based on the node, and the privacy compliance of the target application can be detected according to the detection strategy.
[0140] Among them, for the target application, its life cycle will flow, for example, from application development to offline, so when the life cycle of the target application runs to the target node in the node, the target detection node corresponding to the target node is determined.
[0141] For example, for a target APP, when the life cycle of the target APP runs to an application development node in a node, it indicates that the R&D personnel are currently developing codes for the target APP locally. At this time, the application development detection node corresponding to the application development node is determined.
[0142] In addition, for different detection nodes, the corresponding detection mechanisms are different, that is, there are different detection strategies, which can realize privacy compliance detection at different nodes in the life cycle of the target application.
[0143] Therefore, for a target detection node, the detection strategy corresponding to the target detection node can be determined, and then the privacy compliance of the target application can be detected by using the detection strategy corresponding to the target detection node.
[0144] Through the above description of the technical solution provided in the embodiment of the present application, a detection node set is obtained, and the target application, the detection nodes in the detection node set and the nodes in the life cycle of the target application are determined to correspond one-to-one. When the life cycle of the target application runs to the target node in the node, the target detection node corresponding to the target node is determined, and the privacy compliance of the target application is detected using the detection strategy corresponding to the target detection node.
[0145] By obtaining a set of detection nodes and determining the target application, when the life cycle of the target application runs to the target node in the node, the target detection node corresponding to the target node is determined, and the privacy compliance of the target application is detected using the detection strategy corresponding to the target detection node. In this way, privacy compliance detection can be achieved within the life cycle of the application.
[0146] In an embodiment of the present application, for the life cycle of the target application, when it is executed to the application development node, that is, at this moment, it reaches the node where the R&D personnel develop the code of the target application locally, it is necessary to provide a detection mechanism suitable for the application development node.
[0147] Based on this, the embodiment of the present application writes a plug-in through Idea (referring to IntelliJ IDEA, which is an integrated development environment (IDE) and can be translated into Chinese as "intelligent development environment" or "integrated development environment"), creates a detection Action (in the IDEA plug-in, Action refers to an operation action of IDEA. The plug-in author can create and register these actions to IDEA to achieve specific functions. Here it refers to the creation of an action to detect the privacy API) and adds detection rules for files such as Java, AndroidManifest.xml, kotlin, etc., and after verifying that the detection rules are feasible locally, publish the plug-in to the local to obtain the plug-in package, such as the format of XXX.ZIP, etc., and finally provide the plug-in package to various R&D personnel for use.
[0148] For developers, when installing the plug-in and developing the target application code locally, the plug-in will scan and detect all the code of the current file (such as Java, AndroidManifest.xml, kotlin and other files) within the scope of the developer's authorization. For example, when traversing and detecting sequentially combined codes, if relevant privacy API (Application Program Interface) calls are detected in all the codes of the current file, the developer will be reminded to pay attention to the current API, for example by marking it in red.
[0149] This enables the detection of application development nodes in the life cycle of the target application. When developers are developing the code of the target application locally, if there are issues related to calling privacy APIs, the developers will be prompted in real time, blocking privacy compliance issues at the root.
[0150] Based on this, Figure 2 FIG. 1 is a schematic diagram of an implementation flow of another privacy compliance detection method provided in an embodiment of the present application. The method is applied to an electronic device and may specifically include the following steps:
[0151] S201, obtaining a detection node set.
[0152] In the embodiment of the present application, this step is similar to the above-mentioned step S101, and the embodiment of the present application will not be described one by one here.
[0153] S202, determining a target application, wherein the detection nodes in the detection node set correspond one-to-one to the nodes in the life cycle of the target application.
[0154] In the embodiment of the present application, this step is similar to the above-mentioned step S102, and the embodiment of the present application will not be described one by one here.
[0155] S203: When the life cycle runs to an application development node in the node, determine an application development detection node corresponding to the application development node.
[0156] In an embodiment of the present application, for the life cycle of the target application, when the life cycle of the target application runs to the application development node in the node, it means that it is proceeding to the node where the code of the target application is developed locally by the R&D personnel. At this time, it is necessary to detect the call of the privacy API in the code of the target application developed locally by the R&D personnel. To this end, it is necessary to determine the application development detection node corresponding to the application development node, so as to execute the detection mechanism of the application development node.
[0157] S204, searching for an integrated development environment plug-in associated with the application development detection node, and calling the integrated development environment plug-in to perform the following detection operations.
[0158] S205, obtaining the current code in the application development file of the target application, and detecting whether there is a call to the privacy application programming interface in the current code.
[0159] S206: If there is a call, mark the privacy application programming interface in the current code.
[0160] In an embodiment of the present application, an integrated development environment plug-in is written through Idea, a detection Action is created, and detection rules for files such as Java, AndroidManifest.xml, and kotlin are added. After locally verifying that the detection rules are feasible, the integrated development environment plug-in is published to the local to obtain the plug-in package, and finally the plug-in package is provided to various R&D personnel for use.
[0161] For developers, install the IDE plug-in, and in the process of developing the target application code locally, that is, the life cycle of the target application runs to the application development node in the node. At this time, find the IDE plug-in corresponding to the application development detection node, and call the IDE plug-in to perform the following privacy compliance detection operations:
[0162] The current code in the application development file of the target application is obtained, and whether there is a call to the privacy application programming interface in the current code is detected. If there is a call to the privacy application programming interface in the current code, the privacy application programming interface in the current code is marked.
[0163] For example, in the process of developing the target APP code locally, that is, the life cycle of the target APP runs to the application development node in the node. At this time, the integrated development environment plug-in (such as Idea plug-in) corresponding to the application development detection node is found, and the integrated development environment plug-in is called to perform the following privacy compliance detection operations:
[0164] Get the current code in the target file, such as APPJava, AndroidManifest.xml, kotlin and other files, and detect whether there are calls to the privacy API in the current code. If there are calls to the privacy API in the current code, determine the specific location of the privacy API in the current code and mark the specific location in red to mark the privacy API and remind R&D personnel to pay attention.
[0165] In an embodiment of the present application, a privacy application programming interface data (or a privacy application programming interface list) is provided, wherein the privacy application programming interface data includes at least one privacy application programming interface, and the privacy application programming interface data is used to detect whether there is a call to the privacy application programming interface in the current code.
[0166] Specifically, privacy application programming interface data is obtained, the privacy application programming interface data includes at least one privacy application programming interface, the application programming interfaces in the current code are traversed, and it is determined whether the application programming interface matches the privacy application programming interface in the privacy application programming interface data. If there is a match, it is determined that there is a call to the privacy application programming interface in the current code; if there is no match, it is determined that there is no call to the privacy application programming interface in the current code.
[0167] Through the above description of the technical solution provided in the embodiment of the present application, a detection mechanism suitable for application development nodes in the life cycle of the target application is provided, which can implement privacy compliance detection of application development nodes in the life cycle of the target application. When R&D personnel are developing the code of the target application locally, if there are issues related to calling the privacy API, the R&D personnel will be prompted in real time, thus blocking the privacy compliance issues at the source.
[0168] In an embodiment of the present application, for the life cycle of the target application, when it runs to an offline node in the node, that is, when it reaches the node where the tester tests the target application offline, it is necessary to provide a detection mechanism suitable for the offline node.
[0169] Based on this, the embodiment of the present application uses application tools to decompile apk (apk is the file extension of the packaged file of the Android application, which can be translated into "Android application package" in Chinese), dex (dex is the abbreviation of Dalvik Executable, which can be translated into "Dalvik executable file" in Chinese, and is a bytecode file format specific to the Android platform), jar (jar is the abbreviation of Java Archive, which can be translated into "Java archive file" in Chinese. The jar file is a compressed file format for storing and distributing Java classes, resource files and other related files), and other files, and then use the bytecode tool in the bytecode operation framework component to read the bytecode content of the class file, and use the parsing library tool library to read the file content of the AndroidManifest file, and then parse whether it contains relevant privacy API calls or definitions of relevant high-risk permissions. If so, they are displayed on the page and saved in the report.
[0170] This enables privacy compliance testing of offline nodes in the target application's life cycle. Before the target application is put on the market, testers can detect the calls to the target application's privacy API in advance, which can reduce the risk of failure in the target application's launch.
[0171] In addition, for the life cycle of the target application, when it runs to the application self-starting node, that is, at this moment, it reaches the node where the tester performs a self-starting test on the target application, a self-starting detection mechanism suitable for the application self-starting node needs to be provided.
[0172] Based on this, the embodiment of the present application uses the debug bridge tool to capture the operation log. After obtaining all the operation logs of the target application, they are filtered and screened. If there are any suspected self-start related operation logs, they are displayed on the interface and different colors are attached according to the level for easy viewing. It is used to detect whether the target application has a self-start problem.
[0173] The final visualization interface uses visualization tools to display the content presentation interface containing different levels of colors.
[0174] This can realize the application self-start detection of the application self-start node in the life cycle of the target application. Before the target application is put on the market, the tester can detect in advance whether the target application has self-start problems, which can reduce the risk of failure of the target application to be put on the market.
[0175] Based on this, Figure 3 FIG. 1 is a schematic diagram of an implementation flow of another privacy compliance detection method provided in an embodiment of the present application. The method is applied to an electronic device and may specifically include the following steps:
[0176] S301, obtaining a detection node set.
[0177] In the embodiment of the present application, this step is similar to the above-mentioned step S101, and the embodiment of the present application will not be described one by one here.
[0178] S302, determining a target application, wherein the detection nodes in the detection node set correspond one-to-one to the nodes in the life cycle of the target application.
[0179] In the embodiment of the present application, this step is similar to the above-mentioned step S102, and the embodiment of the present application will not be described one by one here.
[0180] S303: When the life cycle of the target application runs to an offline node in the node, determine an offline detection node corresponding to the offline node.
[0181] In an embodiment of the present application, for the life cycle of the target application, when the life cycle of the target application runs to the offline node in the node, it means that it has reached the node where the tester tests the target application offline. At this time, it is necessary to detect the call status of the privacy API in the target application. For this purpose, it is necessary to determine the offline detection node corresponding to the offline node, so as to execute the detection mechanism of the offline detection node.
[0182] S304: When the target detection node is an offline detection node, perform the following privacy compliance detection operation.
[0183] S305, decompile the target application program's files to obtain class files and manifest files.
[0184] S306, obtaining the bytecode content in the class file and the file content of the manifest file.
[0185] S307, determining whether there is a call to a privacy application programming interface in the bytecode content and the file content.
[0186] S308, when there is a call, display the privacy application programming interface and save it in the privacy compliance detection report.
[0187] In the embodiment of the present application, for the target detection node, when the target detection node is an offline detection node, it means that at this moment, the node where the tester performs offline testing on the target application needs to execute the detection mechanism of the offline detection node, and the following privacy compliance detection operation is performed for this purpose:
[0188] Decompile the target application's files using a decompilation tool to obtain class files and manifest files. Use a bytecode tool to read the bytecode content in the class file. Use a manifest parsing library to read the file content of the manifest file. Determine whether there are calls to the privacy application programming interface in the bytecode content and file content. If there are calls to the privacy application programming interface in the bytecode content and file content, display the privacy application programming interface and save it in the privacy compliance detection report. In addition, it is also possible to determine whether there are definitions of high-risk permissions in the bytecode content and file content. If there are definitions of high-risk permissions in the bytecode content and file content, display the definitions of high-risk permissions and save them in the privacy compliance detection report. It should be noted that a permission may affect the user's privacy security or undermine the stability of the mobile phone system. For example, the permission to obtain sensitive information such as location information and phone book without the user's explicit consent may be considered a high-risk permission.
[0189] For example, the offline detection mechanism of the target APP can be: use application tools to decompile the apk, dex, jar and other files of the target APP to obtain class files and AndroidManifest files, use the bytecode tool in the bytecode framework component to read the bytecode content in the class file, and use the parsing library tool to read the AndroidManifest file content, and then determine whether it contains calls to related privacy APIs or definitions of related high-risk permissions. If so, display them on the interface and save them in the privacy compliance detection report.
[0190] In addition, when the life cycle of the target application runs to the application self-start node in the node, the following application self-start detection operations are performed: capture the running log of the target application, filter the target running log related to the application self-start from the running log; display the target running log, and mark the target running log according to the level of the target running log.
[0191] For example, for the target APP, its self-start detection can be: use the debug bridge tool to capture the operation log, and after obtaining all the operation logs of the target application, filter and screen them. If there are suspected self-start related operation logs, they will be displayed on the interface and attached with different colors according to the level for easy viewing.
[0192] Through the above description of the technical solution provided in the embodiment of the present application, a detection mechanism applicable to offline nodes in the life cycle of the target application is provided, and a self-start detection mechanism applicable to application self-start nodes in the life cycle of the target application is provided. Privacy compliance detection of offline nodes in the life cycle of the target application and application self-start detection of application self-start nodes in the life cycle of the target application can be implemented. Before the target application is put on the market, testers can detect the call status of the privacy API of the target application and self-start problems in advance, which can reduce the risk of failure of the target application to be put on the market.
[0193] In addition, for the life cycle of the target application, when it runs to the code editing node in the node, that is, at this moment, it reaches the node where the developer modifies the code of the target application, a detection mechanism suitable for the code editing node needs to be provided.
[0194] Based on this, the embodiment of the present application creates a lintCheck task through a custom build tool plug-in. When the developer initiates a "merge request" or "merge application" (a "merge request" or "merge application" is a request submitted by the developer to the code repository, requesting that the modified code be merged with the main branch or other branches), the above task is executed, and then the git diff (in Git, the git diff command is used to compare file differences, that is, compare the differences between files in the temporary storage area and the working area) command is used to collect all changed files and changed line numbers into a collection. Finally, the collection is handed over to a custom code static analysis tool to detect whether the changed place contains related privacy API call issues. If so, the calling file and the specific line number of the call will be output in the report for easy viewing by testers and developers.
[0195] This enables privacy compliance detection of code editing nodes in the target application lifecycle. When the code is merged, the privacy API call status of the code modified by the developer can be automatically detected, which will prompt the developer in real time and block privacy compliance issues at the root.
[0196] Based on this, Figure 4 FIG. 1 is a schematic diagram of an implementation flow of another privacy compliance detection method provided in an embodiment of the present application. The method is applied to an electronic device and may specifically include the following steps:
[0197] S401, obtaining a detection node set.
[0198] In the embodiment of the present application, this step is similar to the above-mentioned step S101, and the embodiment of the present application will not be described one by one here.
[0199] S402, determining a target application, wherein the detection nodes in the detection node set correspond one-to-one to the nodes in the life cycle of the target application.
[0200] In the embodiment of the present application, this step is similar to the above-mentioned step S102, and the embodiment of the present application will not be described one by one here.
[0201] S403: When the life cycle of the target application runs to a code editing node in the node, determine a code editing detection node corresponding to the code editing node.
[0202] In an embodiment of the present application, for the life cycle of the target application, when the life cycle of the target application runs to the code editing node in the node, it means that at this moment it has reached the node where the R&D personnel make changes to the code of the target application. At this time, it is necessary to detect the call situation of the privacy API for the modified code. For this purpose, it is necessary to determine the code editing detection node corresponding to the code editing node, so as to execute the detection mechanism of the code editing node.
[0203] S404, searching for a task corresponding to the code editing detection node, and performing the following privacy compliance detection operation through the task when a code merge request is triggered.
[0204] S405, determining the file of the target application program where code editing occurs, and the code line number where code editing occurs.
[0205] S406, saving the file where the code editing occurs and the code line number where the code editing occurs into the detection set.
[0206] S407, detecting whether there is a call to a privacy application programming interface in the detection set.
[0207] S408, when there is a call, output the file and code line number that calls the privacy application programming interface in the privacy compliance detection report.
[0208] In the embodiment of the present application, a static code checking tool is used to implement CI (Continuous Integration, which means that developers frequently merge code into a shared code repository and verify the correctness of the code through automated build and test processes) to automatically perform privacy API detection on newly added files or newly modified code when merging requests. The goal of continuous integration is to discover and resolve code integration issues as early as possible, ensuring that team members' code can be seamlessly integrated into the main branch.
[0209] To this end, a code detection task is created through a custom build tool plug-in to find the task corresponding to the code editing detection node. When the developer initiates a merge request, that is, when the code merge request is triggered, the following privacy compliance detection operations are performed through the above task:
[0210] Determine the files where code editing occurs and the line numbers where the code editing occurs in the target application, save the files where code editing occurs and the line numbers where the code editing occurs in the detection set, use a customized static code detection tool to detect whether there are calls to the privacy application programming interface in the detection set, and if there are calls to the privacy application programming interface in the detection set, output the files and line numbers that call the privacy application programming interface in the privacy compliance detection report.
[0211] Through the above description of the technical solution provided in the embodiment of the present application, a detection mechanism suitable for the life cycle code editing nodes in the target application is provided, which can realize the privacy compliance detection of the code editing nodes in the life cycle of the target application, and automatically detect the privacy API call status of the code modified by the R&D personnel when the code is merged, which will prompt the R&D personnel in real time and block the privacy compliance issues at the root.
[0212] In addition, in an embodiment of the present application, for the life cycle of the target application, when it runs to an online node in the node, that is, when the R&D personnel release the target application to the online node, it is necessary to provide a detection mechanism suitable for the online node.
[0213] Based on this, the embodiment of the present application executes the first function + asm to convert the input .class file into the target bytecode file, parses the class files compiled by the target application one by one, and obtains the pre-prepared tool class that needs to be replaced. Execute the second function + asm to convert the input .class file into the target bytecode file, parses the remaining compiled class files of the target application one by one, and analyzes whether it contains calls to the relevant bytecodes of the privacy API. If so, replace the current bytecode instructions with asm to the method instructions corresponding to the tool class obtained in the first step. Finally, recompile the target application, release the recompiled installation package to the market, implement online monitoring based on the privacy API call reported by the user, and intercept or open certain special APIs through the honeycomb online parameter control and other management and dynamic adjustment strategies.
[0214] In this way, privacy compliance detection of online nodes in the target application life cycle can be achieved. The target application is released online, supporting the replacement of online privacy APIs, and the online privacy API interception supports dynamic configuration distribution, making the API interception more flexible for many years. The privacy API call cache is implemented, reducing the call frequency.
[0215] Based on this, as Figure 5 shown, it is a schematic diagram of the implementation process of another privacy compliance detection method provided by an embodiment of the present application. This method is applied to an electronic device and specifically may include the following steps:
[0216] S501, obtain a set of detection nodes.
[0217] In the embodiment of the present application, this step is similar to step S101 above, and the embodiment of the present application will not elaborate here one by one.
[0218] S502, determine the target application. The detection nodes in the set of detection nodes correspond one by one to the nodes in the life cycle of the target application.
[0219] In the embodiment of the present application, this step is similar to step S102 above, and the embodiment of the present application will not elaborate here one by one.
[0220] S503, when the life cycle of the target application runs to the online node in the node, determine the online detection node corresponding to the online node.
[0221] In the embodiment of the present application, for the life cycle of the target application, when the life cycle of the target application runs to the online node in the node, it means that at this moment, it reaches the node where the R & D personnel release the target application online. At this time, it is necessary to detect the call situation of the privacy API in the target application. Therefore, it is necessary to determine the online detection node corresponding to the online node to facilitate the execution of the detection mechanism of the online node.
[0222] S504, find the first parsing tool and the second parsing tool corresponding to the online detection node, and perform the following privacy compliance detection operations.
[0223] S505, through the first parsing tool, parse the class file of the target application to obtain the pre-configured tool class.
[0224] S506, through the second parsing tool, parse the remaining class files of the target application to obtain the parsing result.
[0225] S507, analyze whether there is a call to the privacy application programming interface in the parsing result.
[0226] S508, in the case of a call, determining the call bytecode instruction corresponding to the privacy application programming interface (the authority to be determined is determined within the user's authority).
[0227] S509, replacing the calling bytecode instruction with the corresponding bytecode instruction in the tool class.
[0228] S510, recompile the target application to obtain data of the target application.
[0229] In an embodiment of the present application, for a target application, its privacy API call situation can be detected online, and if there is a privacy API call, the privacy API can be automatically replaced.
[0230] To this end, find the first parsing tool and the second parsing tool corresponding to the online detection node. Both the first parsing tool and the second parsing tool here convert the input .class file into the target bytecode file function + asm, and perform the following privacy compliance detection operations:
[0231] Through the first parsing tool, the class files of the target application are parsed one by one to obtain a pre-configured tool class. Through the second parsing tool, the remaining class files of the target application (referring to the class files other than the class files corresponding to the tool class) are parsed one by one to obtain the parsing results. It is analyzed whether there is a call to the privacy application programming interface in the parsing results. When there is a call to the privacy application programming interface in the parsing results, the calling bytecode instructions corresponding to the privacy application programming interface are determined, and the calling bytecode instructions are replaced with the corresponding bytecode instructions in the tool class. The target application is recompiled to obtain the data of the target application. The data here is the installation package of the target application, and the installation package needs to be published.
[0232] Through the above description of the technical solution provided in the embodiment of the present application, a detection mechanism suitable for online nodes in the life cycle of a target application is provided, which can detect the call of the privacy API online, and if there is a call to the privacy API, the privacy API can be automatically replaced, and the online privacy API interception supports dynamic configuration and distribution, making API interception more flexible for many years, realizing privacy API call caching, and reducing the call frequency.
[0233] Corresponding to the above method embodiment, the present application embodiment also provides a privacy compliance detection device, such as Figure 6 As shown, the device may include: a collection acquisition module 610, a program determination module 620, and a privacy compliance detection module 630.
[0234] A set acquisition module 610 is used to acquire a detection node set;
[0235] A program determination module 620, configured to determine a target application, wherein the detection nodes in the detection node set correspond one-to-one to the nodes in the life cycle of the target application;
[0236] The privacy compliance detection module 630 is used to determine a detection strategy based on the node, and detect the privacy compliance of the target application according to the detection strategy.
[0237] In an optional implementation, the privacy compliance detection module specifically includes:
[0238] A node determination submodule, used for determining a target detection node corresponding to the target node when the life cycle runs to the target node in the node;
[0239] The privacy compliance detection submodule is used to detect the privacy compliance of the target application using the detection strategy associated with the target detection node.
[0240] In an optional implementation, the node determination submodule is specifically used to:
[0241] When the life cycle runs to an application development node in the nodes, an application development detection node corresponding to the application development node is determined.
[0242] In an optional implementation, the privacy compliance detection submodule specifically includes:
[0243] A plug-in search unit, used to search for an integrated development environment plug-in associated with the application development detection node;
[0244] The plug-in calling unit is used to call the integrated development environment plug-in to perform the following detection operations:
[0245] A code acquisition unit, used to acquire the current code in the application development file of the target application;
[0246] A code detection unit, used to detect whether there is a call to a privacy application programming interface in the current code;
[0247] An interface marking unit is used to mark the privacy application programming interface in the current code when there is a call.
[0248] In an optional implementation, the code detection unit is specifically used to:
[0249] Get privacy API data;
[0250] Traversing the application programming interface in the current code, and determining whether the application programming interface matches the privacy application programming interface in the privacy application programming interface data;
[0251] In the case of a match, determining that a call to the privacy application programming interface exists in the current code;
[0252] If there is no match, it is determined that there is no call to the privacy application programming interface in the current code.
[0253] In an optional implementation, the node determination submodule is specifically used to:
[0254] When the life cycle runs to an offline node in the nodes, an offline detection node corresponding to the offline node is determined.
[0255] In an optional implementation, the privacy compliance detection submodule is specifically used to:
[0256] When the target detection node is an offline detection node, perform the following privacy compliance detection operation;
[0257] Decompiling the target application program's files to obtain class files and manifest files;
[0258] Obtaining the bytecode content in the class file and the file content of the manifest file;
[0259] Determining whether there is a call to a privacy application programming interface in the bytecode content and the file content;
[0260] If there is a call, the privacy application programming interface is displayed and saved in the privacy compliance detection report.
[0261] In an optional implementation, the privacy compliance detection module is further used to:
[0262] Determine whether there is a definition of high-risk permissions in the bytecode content and the file content;
[0263] In the case where a definition of the high-risk permission exists, the definition of the high-risk permission is displayed and saved in the privacy compliance detection report.
[0264] In an optional embodiment, the device further comprises:
[0265] The self-start detection module is used to perform the following application self-start detection operations when the life cycle runs to the application self-start node in the node:
[0266] Capturing the running log of the target application, and filtering the target running log related to the application self-starting from the running log;
[0267] The target operation log is displayed, and the target operation log is marked according to the level of the target operation log.
[0268] In an optional implementation, the node determination submodule is specifically used to:
[0269] When the life cycle runs to a code editing node in the node, a code editing detection node corresponding to the code editing node is determined.
[0270] In an optional implementation, the privacy compliance detection submodule is specifically used to:
[0271] Find the task corresponding to the code editing detection node, and perform the following privacy compliance detection operations through the task when a code merge request is triggered:
[0272] Determine the file where code editing occurs in the target application, and the code line number where code editing occurs;
[0273] The files where the code editing occurs and the code line numbers where the code editing occurs are saved in the detection set;
[0274] Detecting whether there is a call to a privacy application programming interface in the detection set;
[0275] If there is a call, the file and code line number that call the privacy application programming interface are output in the privacy compliance detection report.
[0276] In an optional implementation, the node determination submodule is specifically used to:
[0277] When the life cycle runs to an online node in the nodes, an online detection node corresponding to the online node is determined.
[0278] In an optional implementation, the privacy compliance detection submodule is specifically used to:
[0279] Find the first parsing tool and the second parsing tool corresponding to the online detection node, and perform the following privacy compliance detection operations;
[0280] Parsing the class file of the target application program through the first parsing tool to obtain a pre-configured tool class;
[0281] Parsing the remaining class files of the target application using the second parsing tool to obtain parsing results;
[0282] Analyzing whether there is a call to a privacy application programming interface in the parsing result;
[0283] If there is a call, determining the call bytecode instruction corresponding to the privacy application programming interface;
[0284] Replacing the calling bytecode instruction with the corresponding bytecode instruction in the tool class;
[0285] The target application is recompiled to obtain data of the target application.
[0286] The present application also provides an electronic device, such as Figure 7 As shown, it includes a processor 71, a communication interface 72, a memory 73 and a communication bus 74, wherein the processor 71, the communication interface 72, and the memory 73 communicate with each other through the communication bus 74.
[0287] A memory 73, for storing computer programs;
[0288] The processor 71 is used to execute the program stored in the memory 73 to implement the following steps:
[0289] Acquire a detection node set; determine a target application, wherein the detection nodes in the detection node set correspond one-to-one to the nodes in the life cycle of the target application; determine a detection strategy based on the nodes, and detect the privacy compliance of the target application according to the detection strategy.
[0290] The communication bus mentioned in the above electronic device can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.
[0291] The communication interface is used for communication between the above electronic device and other devices.
[0292] The memory may include a random access memory (RAM) or a non-volatile memory, such as at least one disk memory. Optionally, the memory may also be at least one storage device located away from the aforementioned processor.
[0293] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0294] In another embodiment provided in the present application, a storage medium is also provided, in which instructions are stored. When the storage medium is run on a computer, the computer executes the privacy compliance detection method described in any of the above embodiments.
[0295] In another embodiment provided in the present application, a computer program product including instructions is also provided, which, when executed on a computer, enables the computer to execute the privacy compliance detection method described in any one of the above embodiments.
[0296] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a storage medium, or transmitted from one storage medium to another storage medium, for example, the computer instructions may be transmitted from a website site, a computer, a server or a data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website site, computer, server or data center. The storage medium may be any available medium that a computer can access or a data storage device such as a server or a data center that includes one or more available media integrations. The available medium may be a magnetic medium, (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive Solid State Disk (SSD)), etc.
[0297] It should be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprising", "including" or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising said element.
[0298] Each embodiment in this specification is described in a related manner. For the same or similar parts among the embodiments, reference can be made to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for system embodiments, since they are basically similar to method embodiments, the description is relatively simple, and reference can be made to the relevant parts of the method embodiments for the relevant content.
[0299] The above description is only a preferred embodiment of the present application and is not intended to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application are all included in the protection scope of the present application.
Claims
1. A privacy compliance detection method, It is characterized in that The method comprises: Get the detection node set; Determine a target application, wherein the detection nodes in the detection node set correspond one-to-one to the nodes in the life cycle of the target application; A detection strategy is determined based on the node, and the privacy compliance of the target application is detected according to the detection strategy.
2. The method according to claim 1, It is characterized in that The step of determining a detection strategy based on the node and detecting the privacy compliance of the target application according to the detection strategy includes: In the case where the life cycle runs to a target node in the node, determining a target detection node corresponding to the target node; The privacy compliance of the target application is detected using the detection strategy associated with the target detection node.
3. The method according to claim 2, It is characterized in that When the life cycle runs to a target node in the node, determining a target detection node corresponding to the target node includes: In a case where the life cycle runs to an application development node in the node, determining an application development detection node corresponding to the application development node; The detecting the privacy compliance of the target application using the detection strategy associated with the target detection node includes: Find the integrated development environment plug-in associated with the application development detection node, and call the integrated development environment plug-in to perform the following detection operations: Obtaining current code in an application development file of the target application, and detecting whether there is a call to a privacy application programming interface in the current code; In the event of a call, the privacy application programming interface in the current code is marked.
4. The method according to claim 3, It is characterized in that The detecting whether there is a call to a privacy application programming interface in the current code includes: Get privacy API data; Traversing the application programming interface in the current code, and determining whether the application programming interface matches the privacy application programming interface in the privacy application programming interface data; In the case of a match, determining that a call to the privacy application programming interface exists in the current code; If there is no match, it is determined that there is no call to the privacy application programming interface in the current code.
5. The method according to claim 2, It is characterized in that When the life cycle runs to a target node in the node, determining a target detection node corresponding to the target node includes: When the life cycle runs to an offline node in the node, determining an offline detection node corresponding to the offline node; The detecting the privacy compliance of the target application using the detection strategy associated with the target detection node includes: When the target detection node is an offline detection node, perform the following privacy compliance detection operation; Decompiling the target application program's files to obtain class files and manifest files; Obtaining the bytecode content in the class file and the file content of the manifest file; Determining whether there is a call to a privacy application programming interface in the bytecode content and the file content; If there is a call, the privacy application programming interface is displayed and saved in the privacy compliance detection report.
6. The method according to claim 5, It is characterized in that After obtaining the bytecode content in the class file and the file content of the manifest file, the method further includes: Determine whether there is a definition of high-risk permissions in the bytecode content and the file content; In the case where a definition of the high-risk permission exists, the definition of the high-risk permission is displayed and saved in the privacy compliance detection report.
7. The method according to claim 2, It is characterized in that The method further comprises: When the life cycle runs to the application self-starting node in the node, the following application self-starting detection operation is performed: Capturing the running log of the target application, and filtering the target running log related to the application self-starting from the running log; The target operation log is displayed, and the target operation log is marked according to the level of the target operation log.
8. The method according to claim 2, It is characterized in that When the life cycle runs to a target node in the node, determining a target detection node corresponding to the target node includes: When the life cycle runs to a code editing node in the node, determining a code editing detection node corresponding to the code editing node; The detecting the privacy compliance of the target application using the detection strategy associated with the target detection node includes: Find the task corresponding to the code editing detection node, and perform the following privacy compliance detection operations through the task when a code merge request is triggered: Determine the file where code editing occurs in the target application, and the code line number where code editing occurs; The files where the code editing occurs and the code line numbers where the code editing occurs are saved in the detection set; Detecting whether there is a call to a privacy application programming interface in the detection set; If there is a call, the file and code line number that call the privacy application programming interface are output in the privacy compliance detection report.
9. The method according to claim 2, It is characterized in that When the life cycle runs to a target node in the node, determining a target detection node corresponding to the target node includes: When the life cycle runs to an online node in the node, determining an online detection node corresponding to the online node; The detecting the privacy compliance of the target application using the detection strategy associated with the target detection node includes: Find the first parsing tool and the second parsing tool corresponding to the online detection node, and perform the following privacy compliance detection operations; Parsing the class file of the target application program through the first parsing tool to obtain a pre-configured tool class; Parsing the remaining class files of the target application using the second parsing tool to obtain parsing results; Analyzing whether there is a call to a privacy application programming interface in the parsing result; If there is a call, determining the call bytecode instruction corresponding to the privacy application programming interface; Replacing the calling bytecode instruction with the corresponding bytecode instruction in the tool class; The target application is recompiled to obtain data of the target application.
10. A privacy compliance detection device, It is characterized in that The device comprises: A collection acquisition module is used to acquire a detection node collection; A program determination module, used to determine a target application, wherein the detection nodes in the detection node set correspond one-to-one to the nodes in the life cycle of the target application; A privacy compliance detection module is used to determine a detection strategy based on the node, and detect the privacy compliance of the target application according to the detection strategy.
11. An electronic device, It is characterized in that It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other through the communication bus; Memory, used to store computer programs; A processor, for implementing the method steps described in any one of claims 1 to 9 when executing a program stored in a memory.
12. A storage medium having a computer program stored thereon, It is characterized in that When the program is executed by a processor, the method according to any one of claims 1 to 9 is implemented.