Method and device for identifying equipment abnormity based on APP application record and computer equipment

By processing and extracting the device record data of mobile terminal devices, and combining with the device privacy risk abnormal location identification network model, the problem that traditional methods cannot accurately identify the device privacy risk abnormal locations is solved, and efficient and accurate identification results are achieved.

CN120030532APending Publication Date: 2025-05-23GUANGZHOU GONETT NETWORK TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510078372.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

Traditional methods of recording and identifying device abnormalities based on APP applications cannot accurately identify the location of abnormal privacy risks that occur in the device.

Method used

By obtaining the device record data of the mobile terminal device, data processing and feature extraction, risk tag feature data are generated, and inputting it into the pre-trained device privacy risk abnormal location identification network model to identify the location information of the device privacy risk abnormal location.

Benefits of technology

Accurate identification of abnormal locations of equipment privacy risks is achieved, identification efficiency and accuracy are improved, data coverage of identification is expanded, and manual intervention is reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030532A_ABST
    Figure CN120030532A_ABST
Patent Text Reader

Abstract

The invention relates to a method and device for identifying equipment abnormity based on APP application records, computer equipment and a storage medium. The method comprises the following steps: acquiring equipment record data of mobile terminal equipment installed by a first preset number of case-related software applications; wherein the equipment record data comprises equipment application installation list data; performing data processing on the equipment record data to obtain corresponding processed equipment record data; performing feature extraction processing on the processed equipment record data to obtain risk tag feature data of the corresponding mobile terminal equipment; wherein the risk tag feature data comprises risk software application feature data, risk mobile terminal device feature data and risk wireless network feature data; and inputting the risk tag feature data into a pre-trained equipment privacy risk abnormal site identification network model to obtain position information of a corresponding equipment privacy risk abnormal site. By adopting the method, the efficiency and the accuracy can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of mobile device application security technology, and in particular to a method, apparatus, computer equipment and storage medium for identifying device anomalies based on APP application records. Background Art

[0002] With the popularization of mobile Internet, the installation and use of various software applications have become part of people's daily lives, which also provides criminals with opportunities to use software applications to commit illegal activities. Therefore, it is particularly important to identify whether the device address of the device where the software application is installed is an abnormal location with device privacy risks.

[0003] However, the traditional method of identifying device anomalies based on APP application records has problems such as being unable to accurately identify abnormal locations where devices pose privacy risks. Summary of the invention

[0004] Based on this, it is necessary to provide a method, device, computer equipment and storage medium for identifying device anomalies based on APP application records, which can accurately identify abnormal locations where privacy risks occur in the device, in response to the above technical problems.

[0005] In a first aspect, a method for identifying device abnormalities based on APP application records is provided, the method comprising:

[0006] Obtaining device record data of a first preset number of mobile terminal devices on which the software application involved in the case is installed; wherein the device record data includes device application installation list data;

[0007] Performing data processing on the recorded data of each device to obtain the corresponding processed recorded data of the device;

[0008] Perform feature extraction processing on each processed device record data to obtain risk label feature data of the corresponding mobile terminal device; wherein the risk label feature data includes risk software application feature data, risk mobile terminal device feature data and risk wireless network feature data;

[0009] The feature data of each risk label is input into the pre-trained device privacy risk abnormal location identification network model to obtain the location information of the corresponding device privacy risk abnormal location.

[0010] In one embodiment, data processing is performed on each device record data to obtain corresponding processed device record data, including:

[0011] Perform data cleaning on the recorded data of each device to obtain the corresponding cleaned device recorded data;

[0012] In response to performing a configuration operation on the data screening parameter, determining the data screening parameter;

[0013] Data screening is performed on each cleaned device record data according to the data screening parameters to obtain corresponding processed device record data.

[0014] In one embodiment, the method further comprises:

[0015] Obtain historical label feature data of a second preset number of mobile terminal devices; wherein the historical label feature data includes historical feature data of risky software applications, historical feature data of risky mobile terminal devices, and historical feature data of risky wireless networks; perform random division processing on each historical label feature data to generate a training sample set and a test sample set; train a preset device privacy risk abnormal location identification initial network model according to the training sample set, and test the device privacy risk abnormal location identification initial network model according to the test sample set, adjust model parameters of the device privacy risk abnormal location identification initial network model based on indicators obtained from training and testing until the indicators meet preset requirements, generate a device privacy risk abnormal location identification network model, and output location information of each device privacy risk abnormal location based on the device privacy risk abnormal location identification network model.

[0016] In one embodiment, the method includes: encoding each location information based on a Geohash algorithm to obtain a corresponding location information character string.

[0017] In one embodiment, the method includes: based on a cluster analysis algorithm, performing cluster analysis on each location information character string to obtain a high-density risk area; performing statistical analysis on each location information according to the high-density risk area to obtain corresponding target location information; the target location information is the location information within the high-density risk area; performing statistical analysis on each target location information and the risk mobile terminal device characteristic data of the corresponding target location information to obtain the terminal number of the risk mobile terminal of the corresponding target location information; determining the total number of terminals in the high-density risk area according to the sum of the numbers of each terminal; in response to the total number of terminals being greater than or equal to a total number threshold, determining the high-density risk area as an abnormally concentrated area of ​​device privacy risk.

[0018] In one of the embodiments, in response to the total number of terminals being greater than or equal to a total number threshold, determining the high-density risk area as an area with abnormally concentrated device privacy risks also includes: inputting the risk label feature data corresponding to each target location information into a pre-trained regional privacy risk assessment model to obtain a comprehensive regional privacy risk score for the area with abnormally concentrated device privacy risks; and determining the regional privacy risk level based on the comprehensive regional privacy risk score.

[0019] In one of the embodiments, the method also includes: determining the regional privacy risk statistical results based on the risky wireless network characteristic data corresponding to each target location information, the device privacy risk abnormal aggregation area and the regional privacy risk level; the regional privacy risk statistical results include the regional privacy risk level, the device privacy risk abnormal aggregation area, the total number of terminals corresponding to the device privacy risk abnormal aggregation area and the total number of risky wireless networks corresponding to the device privacy risk abnormal aggregation area; and displaying the regional privacy risk statistical results on the regional privacy risk statistical results display interface.

[0020] In a second aspect, a device for identifying device anomalies based on APP application records is provided, and the device includes a data acquisition module, a data processing module, a feature extraction module and a location identification module.

[0021] Among them, the data acquisition module is used to obtain the device record data of the mobile terminal devices installed with the first preset number of software applications involved in the case; wherein the device record data includes the device application installation list data; the data processing module is used to perform data processing on each device record data to obtain the corresponding processed device record data; the feature extraction module is used to perform feature extraction processing on each processed device record data to obtain the risk label feature data of the corresponding mobile terminal device; wherein the risk label feature data includes risk software application feature data, risk mobile terminal device feature data and risk wireless network feature data; the location identification module is used to input each risk label feature data into a pre-trained device privacy risk abnormal location identification network model to obtain the location information of the corresponding device privacy risk abnormal location.

[0022] In a third aspect, a computer device is provided. The computer device includes a memory and a processor. The memory stores a computer program. When the processor executes the computer program, the steps of any method in the above method embodiments are implemented.

[0023] In a fourth aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of any method in the above method embodiments are implemented.

[0024] The above-mentioned method, apparatus, computer equipment and storage medium for identifying device anomalies based on APP application records obtain the device record data of the mobile terminal devices on which the first preset number of software applications involved in the case are installed; wherein the device record data includes the device application installation list data; then, data processing is performed on each device record data to obtain the corresponding processed device record data; then, feature extraction processing is performed on each processed device record data to obtain the risk label feature data of the corresponding mobile terminal device; wherein the risk label feature data includes risk software application feature data, risk mobile terminal device feature data and risk wireless network feature data; then, each risk label feature data is input into a pre-trained device privacy risk abnormal location identification network model to obtain the location information of the corresponding device privacy risk abnormal location, which can accurately identify the abnormal location where the device has privacy risks, thereby improving the recognition efficiency and accuracy, expanding the data coverage of the recognition, and reducing manual intervention. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 This is an application environment diagram of a method for identifying device abnormalities based on APP application records in one embodiment;

[0026] Figure 2 A first flow chart of a method for identifying device abnormalities based on APP application records in one embodiment;

[0027] Figure 3 A schematic diagram of a flow chart of performing data processing on each device record data to obtain corresponding processed device record data in one embodiment;

[0028] Figure 4 A second flow chart of a method for identifying device abnormalities based on APP application records in one embodiment;

[0029] Figure 5 A third flow chart of a method for identifying device abnormalities based on APP application records in one embodiment;

[0030] Figure 6 A fourth flow chart of a method for identifying device abnormalities based on APP application records in one embodiment;

[0031] Figure 7 It is a structural block diagram of a device for identifying device abnormalities based on APP application records in one embodiment;

[0032] Figure 8 FIG. 4 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0033] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0034] In order to facilitate understanding of the present application, the present application will be described more fully below with reference to the relevant drawings. Embodiments of the present application are provided in the drawings. However, the present application can be implemented in many different forms and is not limited to the embodiments described herein. On the contrary, the purpose of providing these embodiments is to make the disclosure of the present application more thorough and comprehensive.

[0035] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which this application belongs. The terms used herein in the specification of this application are only for the purpose of describing specific embodiments and are not intended to limit this application.

[0036] It is understood that the terms "first", "second", etc. used in this application may be used herein to describe various elements, but these elements are not limited by these terms. These terms are only used to distinguish a first element from another element. For example, without departing from the scope of this application, a first resistor may be referred to as a second resistor, and similarly, a second resistor may be referred to as a first resistor. Both the first resistor and the second resistor are resistors, but they are not the same resistor.

[0037] It can be understood that the “connection” in the following embodiments should be understood as “electrical connection”, “communication connection”, etc. if the connected circuits, modules, units, etc. have electrical signals or data transmission between each other.

[0038] When used herein, the singular forms "a", "an", and "said / the" may also include plural forms, unless the context clearly indicates otherwise. It should also be understood that the terms "include / comprise" or "have" etc. specify the presence of stated features, wholes, steps, operations, components, parts or combinations thereof, but do not exclude the possibility of the presence or addition of one or more other features, wholes, steps, operations, components, parts or combinations thereof.

[0039] The method for identifying device anomalies based on APP application records provided in this application can be applied to Figure 1In the application environment shown. Among them, the mobile terminal device 102 communicates with the server 104 through the network. Among them, the mobile terminal device 102 can be but not limited to various personal computers, laptops, smart phones, tablet computers and portable wearable devices, and the server 104 can be implemented by an independent server or a server cluster composed of multiple servers. It can be understood that the method for identifying device anomalies based on APP application records can also be called a method for identifying device privacy risk abnormal locations, and the device for identifying device anomalies based on APP application records can also be called a device privacy risk abnormal location identification device.

[0040] In one embodiment, Figure 2 As shown, a method for identifying device anomalies based on APP application records is provided, and the method is applied to Figure 1 The server 104 in the example is used for explanation, and the following steps are included: step 201 to step 204.

[0041] Step 201, obtaining device record data of a first preset number of mobile terminal devices on which the software application involved in the case is installed.

[0042] The device record data includes device application installation list data. Specifically, the server 104 may obtain device record data of a first preset number of mobile terminal devices on which the software application involved in the case is installed.

[0043] In a specific example, the server 104 may, but is not limited to, obtain the device record data of the first preset number of mobile terminal devices installed with the software application involved in the case through the government system database. In addition, the acquisition of device record data is carried out in accordance with the "Personal Information Protection Law of the People's Republic of China" and data compliance requirements. The above is only a specific example. In actual applications, it is flexibly set according to user needs and is not limited here.

[0044] In a specific example, the device record data also includes device wireless network connection data, device attribute data and device trajectory data. Device attribute data includes device brand and model, permanent address, permanent latitude and longitude, IMEI code, IMSI code, mobile phone number and MAC code. Device trajectory data includes location data of each device behavior trajectory. Device wireless network connection data includes wireless network name, wireless network MAC address, wireless network whitelist and wireless network blacklist. The above are only specific examples. In actual applications, they are flexibly set according to user needs and are not limited here.

[0045] Step 202: Process the recorded data of each device to obtain the corresponding processed recorded data of the device.

[0046] Specifically, the server 104 processes the recorded data of each device to obtain the corresponding processed recorded data of the device.

[0047] In one embodiment, Figure 3 As shown, data processing is performed on each device record data to obtain corresponding processed device record data, including steps 301 to 303.

[0048] Step 301, performing data cleaning processing on each device record data to obtain the corresponding cleaned device record data;

[0049] Step 302, in response to performing a configuration operation on the data screening parameter, determining the data screening parameter;

[0050] Step 303: Perform data screening processing on each cleaned device record data according to the data screening parameters to obtain corresponding processed device record data.

[0051] Specifically, the server 104 performs data cleaning processing on each device record data to obtain the corresponding cleaned device record data; then, in response to the configuration operation on the data screening parameters, the data screening parameters are determined; then, data screening processing is performed on each cleaned device record data according to the data screening parameters to obtain the corresponding processed device record data, thereby facilitating the removal of duplicate data, invalid data and abnormal data, and facilitating the screening of data that does not meet the application screening conditions, location screening conditions and time screening conditions, thereby improving the efficiency and convenience of identifying abnormal locations of device privacy risks.

[0052] In a specific example, the data screening parameters may include, but are not limited to, application screening conditions, location screening conditions, and time screening conditions. The application screening conditions may include, but are not limited to, the application classification, installation time, usage frequency, and risk type of the software application involved. The location screening conditions may include, but are not limited to, the permanent use location, the residential use location, the domestic use location, or the overseas use location; the time screening conditions include the use time interval.

[0053] In this embodiment, data cleaning is performed on each device record data to obtain corresponding cleaned device record data; then, in response to a configuration operation on the data screening parameter, the data screening parameter is determined; then, data screening is performed on each cleaned device record data according to the data screening parameter to obtain corresponding processed device record data, thereby facilitating the removal of duplicate data, invalid data and abnormal data, and facilitating the screening of data that does not meet the application screening conditions, location screening conditions and time screening conditions, thereby improving the efficiency and convenience of identifying abnormal locations of device privacy risks. The above are only specific examples, which are flexibly set according to user needs in actual applications and are not limited here.

[0054] Step 203: Perform feature extraction processing on each processed device record data to obtain risk label feature data of the corresponding mobile terminal device.

[0055] Among them, the risk label feature data includes risk software application feature data, risk mobile terminal device feature data and risk wireless network feature data; specifically, the server 104 performs feature extraction processing on each processed device record data to obtain the risk label feature data of the corresponding mobile terminal device.

[0056] In a specific example, risky software application characteristic data is characteristic data used to describe the risk type of risky software applications; the risk types of risky software applications include software applications involved in the case, co-installed software applications involved in the case, high-risk homologous software applications, co-installed sensitive software applications, and fraud-related software applications. Risky mobile terminal device characteristic data is characteristic data used to describe risky mobile terminal devices. Risky mobile terminal devices may include, but are not limited to, suspected developer devices, suspected customer service devices, suspected GOIP devices, and suspected suspect devices. Risky wireless network characteristic data is characteristic data used to describe risky wireless networks. The above are only specific examples. In actual applications, they are flexibly set according to user needs and are not limited here.

[0057] Step 204 , input each risk tag feature data into a pre-trained device privacy risk abnormal location identification network model to obtain the location information of the corresponding device privacy risk abnormal location.

[0058] Among them, the device privacy risk abnormal location is the location where the mobile terminal device installed by the software application involved in the case has a privacy risk abnormality. Specifically, the server 104 inputs each risk tag feature data into the pre-trained device privacy risk abnormal location identification network model to obtain the corresponding device privacy risk abnormal location location information, thereby improving the recognition efficiency and accuracy, expanding the recognition data coverage, and reducing manual intervention.

[0059] In a specific example, the location information of the abnormal location of the device privacy risk can be, but is not limited to, the latitude and longitude coordinates of the abnormal location of the device privacy risk. According to the location information of the abnormal location of the device privacy risk, the attribute information of the abnormal location of the device privacy risk can be counted. The attribute information of the abnormal location of the device privacy risk includes the device address, longitude and latitude coordinates, risk level, abnormal location status, suspected location type, location discovery time, location-associated device, location-associated wireless network, and location clue tracing association key. The above are only specific examples. In actual applications, they are flexibly set according to user needs and are not limited here.

[0060] In one embodiment, Figure 4As shown, the method further includes steps 401 to 403.

[0061] Step 401: Acquire historical tag feature data of a second preset number of mobile terminal devices.

[0062] Step 402, randomly divide each historical tag feature data to generate a training sample set and a test sample set;

[0063] Step 403, train the preset device privacy risk abnormal location identification initial network model according to the training sample set, and test the device privacy risk abnormal location identification initial network model according to the test sample set, adjust the model parameters of the device privacy risk abnormal location identification initial network model based on the indicators obtained from the training and testing, until the indicators meet the preset requirements, generate the device privacy risk abnormal location identification network model, and output the location information of each device privacy risk abnormal location based on the device privacy risk abnormal location identification network model.

[0064] Among them, the historical label feature data includes risk software application historical feature data, risk mobile terminal device historical feature data and risk wireless network historical feature data. Specifically, the server 104 obtains the historical label feature data of a second preset number of mobile terminal devices; then, each historical label feature data is randomly divided and processed to generate a training sample set and a test sample set; then, the preset device privacy risk abnormal location identification initial network model is trained according to the training sample set, and the device privacy risk abnormal location identification initial network model is tested according to the test sample set, and the model parameters of the device privacy risk abnormal location identification initial network model are adjusted based on the indicators obtained from the training and testing until the indicators meet the preset requirements, and the device privacy risk abnormal location identification network model is generated, so as to output the location information of each device privacy risk abnormal location based on the device privacy risk abnormal location identification network model, thereby improving the efficiency and convenience of constructing the device privacy risk abnormal location identification network model.

[0065] In this embodiment, historical label feature data of a second preset number of mobile terminal devices are obtained; then, each historical label feature data is randomly divided to generate a training sample set and a test sample set; then, a preset device privacy risk abnormal location identification initial network model is trained according to the training sample set, and the device privacy risk abnormal location identification initial network model is tested according to the test sample set, and the model parameters of the device privacy risk abnormal location identification initial network model are adjusted based on the indicators obtained from the training and testing until the indicators meet the preset requirements, and a device privacy risk abnormal location identification network model is generated, so as to output the location information of each device privacy risk abnormal location based on the device privacy risk abnormal location identification network model, thereby improving the efficiency and convenience of constructing the device privacy risk abnormal location identification network model.

[0066] Based on this, the above-mentioned method for identifying device anomalies based on APP application records obtains the device record data of the mobile terminal devices on which the first preset number of software applications involved in the case are installed; wherein the device record data includes the device application installation list data; then, data processing is performed on each device record data to obtain the corresponding processed device record data; then, feature extraction processing is performed on each processed device record data to obtain the risk label feature data of the corresponding mobile terminal device; wherein the risk label feature data includes risk software application feature data, risk mobile terminal device feature data and risk wireless network feature data; then, each risk label feature data is input into the pre-trained device privacy risk abnormal location identification network model to obtain the location information of the corresponding device privacy risk abnormal location, which can accurately identify the abnormal location where the device has privacy risks, thereby improving the recognition efficiency and accuracy, expanding the data coverage of the recognition, and reducing manual intervention.

[0067] In one embodiment, Figure 5 As shown, the method includes step 501.

[0068] Step 501: Based on the Geohash algorithm, each piece of location information is encoded to obtain a corresponding location information character string.

[0069] Specifically, the server 104 encodes the location information of the abnormal location of the privacy risk of each device based on the Geohash algorithm to obtain the corresponding location information string, thereby reducing data processing time, improving data processing efficiency, and reducing data storage space.

[0070] As a concrete example, here is a simple example of calculating a location information string using Python and the Geohash algorithm:

[0071] import geohash

[0072] #Example longitude and latitude coordinates

[0073] latitude=39.9042

[0074] longitude=116.4074

[0075] # Calculate Geohash code

[0076] geohash_str=geohash.encode(latitude,longitude,precision=8)

[0077] print(f"Geohash code:{geohash_str}")

[0078] #Query adjacent Geohash codes ()

[0079] neighbors=geohash.neighbors(geohash_str)

[0080] print(f"Neighbors Geohash code:{neighbors}")

[0081] The above are only specific examples, which can be flexibly configured according to user needs in actual applications and are not limited here.

[0082] In this embodiment, based on the Geohash algorithm, the location information of the abnormal location of the privacy risk of each device is encoded and processed to obtain the corresponding location information string, thereby reducing data processing time, improving data processing efficiency, and reducing data storage space.

[0083] In one embodiment, Figure 5 As shown, the method includes steps 502 to 506.

[0084] Step 502: Based on the cluster analysis algorithm, cluster analysis is performed on each location information string to obtain a high-density risk area;

[0085] Step 503, statistically analyzing each location information according to the high-density risk area to obtain corresponding target location information;

[0086] Step 504, performing statistical analysis based on each target location information and the risk mobile terminal device characteristic data of the corresponding target location information to obtain the terminal quantity of the risk mobile terminal of the corresponding target location information;

[0087] Step 505, determining the total number of terminals in the high-density risk area according to the sum of the numbers of each terminal;

[0088] Step 506 , in response to the total number of terminals being greater than or equal to the total number threshold, determining the high-density risk area as an abnormally concentrated area of ​​device privacy risks.

[0089] Among them, the target location information is the location information in the high-density risk area. Specifically, based on the cluster analysis algorithm, the server 104 performs cluster analysis on each location information string to obtain a high-density risk area; then, statistical analysis is performed on each location information according to the high-density risk area to obtain the corresponding target location information; then, statistical analysis is performed based on the risk mobile terminal device feature data of each target location information and the corresponding target location information to obtain the number of risk mobile terminals of the corresponding target location information; then, the total number of terminals in the high-density risk area is determined based on the sum of the number of each terminal; finally, in response to the total number of terminals being greater than or equal to the total number threshold, the high-density risk area is determined as an abnormal clustering area of ​​device privacy risks, which improves the statisticalness of the identification results, intelligently identifies suspected crime dens, and improves the efficiency of case analysis.

[0090] In a specific example, the clustering analysis algorithm may include, but is not limited to, DBSCAN, K-means or A-star algorithm. The above are only specific examples, which can be flexibly set according to user needs in actual applications and are not limited here.

[0091] In this embodiment, based on the cluster analysis algorithm, cluster analysis is performed on each location information character string to obtain a high-density risk area; then, statistical analysis is performed on each location information according to the high-density risk area to obtain the corresponding target location information; then, statistical analysis is performed based on the risk mobile terminal device feature data of each target location information and the corresponding target location information to obtain the terminal number of the risk mobile terminal of the corresponding target location information; then, the total number of terminals in the high-density risk area is determined based on the sum of the number of each terminal; finally, in response to the total number of terminals being greater than or equal to the total number threshold, the high-density risk area is determined as an abnormally concentrated area of ​​device privacy risk, which improves the statisticalness of the identification results, intelligently identifies suspected crime dens, and improves the efficiency of case analysis.

[0092] In one embodiment, Figure 6 As shown, in response to the total number of terminals being greater than or equal to the total number threshold, the high-density risk area is determined as the device privacy risk abnormal concentration area, and steps 601 to 602 are also included.

[0093] Step 601, inputting the risk label feature data corresponding to each target location information into a pre-trained regional privacy risk assessment model to obtain a comprehensive regional privacy risk score for the device privacy risk abnormality clustering area;

[0094] Step 602, determining the regional privacy risk level according to the regional privacy risk comprehensive score.

[0095] Specifically, the server 104 can input the risk label feature data corresponding to each target location information into a pre-trained regional privacy risk assessment model to obtain a comprehensive score for the regional privacy risk in the area where device privacy risk is abnormally concentrated; then, the regional privacy risk level is determined based on the comprehensive score for the regional privacy risk, thereby improving the efficiency and convenience of identifying the degree of regional privacy risk in the area where device privacy risk is abnormally concentrated.

[0096] In a specific example, the expression of the regional privacy risk assessment model is as follows:

[0097]

[0098] Among them, z is the comprehensive score of regional privacy risk, W i is the weight of the i-th feature, X i is the feature value of the ith feature. Features may include, but are not limited to, the number of risky software applications involved in the case, the number of sensitive risky software applications, the number of risky mobile terminal devices associated with the case, the number of risky associated cases, the location of abnormal device privacy risk locations, and the number of abnormal device privacy risk locations. i The eigenvalue of the i-th feature can be determined according to the corresponding eigenvector. The above is only a specific example. In actual application, it can be flexibly set according to user needs and is not limited here.

[0099] In this embodiment, the risk label feature data corresponding to each target location information is input into a pre-trained regional privacy risk assessment model to obtain a comprehensive score of the regional privacy risk in the area where device privacy risk is abnormally concentrated; then, the regional privacy risk level is determined based on the comprehensive score of the regional privacy risk, thereby improving the efficiency and convenience of identifying the degree of regional privacy risk in the area where device privacy risk is abnormally concentrated.

[0100] In one embodiment, Figure 6 As shown, the method further includes steps 603 to 604.

[0101] Step 603, determining the regional privacy risk statistics result according to the risky wireless network characteristic data corresponding to each target location information, the device privacy risk abnormality concentration area and the regional privacy risk level.

[0102] Step 604: Display the regional privacy risk statistics results on the regional privacy risk statistics results display interface.

[0103] Among them, the regional privacy risk statistics include the regional privacy risk level, the device privacy risk abnormal clustering area, the total number of terminals corresponding to the device privacy risk abnormal clustering area, and the total number of risky wireless networks corresponding to the device privacy risk abnormal clustering area. Specifically, the server 104 determines the regional privacy risk statistics according to the risky wireless network feature data corresponding to each target location information, the device privacy risk abnormal clustering area, and the regional privacy risk level; then, the regional privacy risk statistics are displayed on the regional privacy risk statistics display interface, which improves the convenience and output efficiency of the result display.

[0104] In this embodiment, the regional privacy risk statistical results are determined based on the risky wireless network characteristic data corresponding to each target location information, the device privacy risk abnormality aggregation area and the regional privacy risk level; then, the regional privacy risk statistical results are displayed on the regional privacy risk statistical results display interface, which improves the convenience and output efficiency of the result display.

[0105] In a specific example, the method further includes:

[0106] Encrypting the regional privacy risk statistical results to obtain encrypted regional privacy risk statistical results;

[0107] Call the VPN application to output the encrypted regional privacy risk statistics to other servers or mobile terminals, thereby broadening the area of ​​collaborative data sharing, improving the security of the results, and ensuring the integrity of the results. The above is only a specific example. In actual applications, it can be flexibly set according to user needs and is not restricted here.

[0108] It should be understood that although Figure 2-6 The steps in the flowchart are shown in sequence as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, Figure 2-6 At least part of the steps may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least part of the sub-steps or stages of other steps.

[0109] Second, as Figure 7 As shown, a device for identifying device anomalies based on APP application records is provided, and the device includes a data acquisition module 710, a data processing module 720, a feature extraction module 730 and a location identification module 740.

[0110] Among them, the data acquisition module 710 is used to obtain the device record data of the mobile terminal devices installed with the first preset number of software applications involved in the case; wherein the device record data includes the device application installation list data; the data processing module 720 is used to perform data processing on each device record data to obtain the corresponding processed device record data; the feature extraction module 730 is used to perform feature extraction processing on each processed device record data to obtain the risk label feature data of the corresponding mobile terminal device; wherein the risk label feature data includes risk software application feature data, risk mobile terminal device feature data and risk wireless network feature data; the location identification module 740 is used to input each risk label feature data into a pre-trained device privacy risk abnormal location identification network model to obtain the location information of the corresponding device privacy risk abnormal location.

[0111] In one embodiment, the data processing module 720 includes a data cleaning unit and a data screening unit.

[0112] Among them, the data cleaning unit is used to perform data cleaning processing on the recorded data of each device to obtain the corresponding cleaned device record data; the data screening unit is used to determine the data screening parameters in response to the configuration operation of the data screening parameters; the data screening unit is used to perform data screening processing on the cleaned device record data according to the data screening parameters to obtain the corresponding processed device record data.

[0113] In one of the embodiments, the device further includes a model building module.

[0114] Among them, the model construction module is used to obtain historical label feature data of a second preset number of mobile terminal devices; wherein the historical label feature data includes historical feature data of risky software applications, historical feature data of risky mobile terminal devices and historical feature data of risky wireless networks; the model construction module is used to randomly divide and process each historical label feature data to generate a training sample set and a test sample set; the model construction module is used to train a preset device privacy risk abnormal location identification initial network model according to the training sample set, and test the device privacy risk abnormal location identification initial network model according to the test sample set, adjust the model parameters of the device privacy risk abnormal location identification initial network model based on the indicators obtained from training and testing until the indicators meet the preset requirements, generate a device privacy risk abnormal location identification network model, and output the location information of each device privacy risk abnormal location based on the device privacy risk abnormal location identification network model.

[0115] In one of the embodiments, the device further includes a data encoding module.

[0116] The data encoding module is used to encode each location information based on the Geohash algorithm to obtain the corresponding location information character string.

[0117] In one embodiment, the device further includes a region division module.

[0118] Among them, the area division module is used to perform cluster analysis on each location information string based on the cluster analysis algorithm to obtain a high-density risk area; the area division module is used to perform statistical analysis on each location information according to the high-density risk area to obtain the corresponding target location information; the target location information is the location information within the high-density risk area; the area division module is used to perform statistical analysis based on the risk mobile terminal device characteristic data of each target location information and the corresponding target location information to obtain the terminal number of the risk mobile terminal of the corresponding target location information; the area division module is used to determine the total number of terminals in the high-density risk area according to the sum of the number of each terminal; the area division module is used to determine the high-density risk area as an abnormally concentrated area of ​​device privacy risk in response to the total number of terminals being greater than or equal to the total number threshold.

[0119] In one embodiment, the device further includes a level evaluation module.

[0120] Among them, the level assessment module is used to input the risk label feature data corresponding to each target location information into the pre-trained regional privacy risk assessment model to obtain the comprehensive score of regional privacy risk in the area where device privacy risk is abnormally concentrated; the level assessment module is used to determine the regional privacy risk level based on the comprehensive score of regional privacy risk.

[0121] In one embodiment, the device further includes a result statistics module.

[0122] Among them, the result statistics module is used to determine the regional privacy risk statistics results based on the risky wireless network characteristic data corresponding to each target location information, the device privacy risk abnormal aggregation area and the regional privacy risk level; the regional privacy risk statistics results include the regional privacy risk level, the device privacy risk abnormal aggregation area, the total number of terminals corresponding to the device privacy risk abnormal aggregation area and the total number of risky wireless networks corresponding to the device privacy risk abnormal aggregation area; the result statistics module is used to display the regional privacy risk statistics results on the regional privacy risk statistics result display interface.

[0123] For the specific limitations of the device for identifying device anomalies based on APP application records, please refer to the limitations of the method for identifying device anomalies based on APP application records above, which will not be repeated here. Each module in the above-mentioned device for identifying device anomalies based on APP application records can be implemented in whole or in part by software, hardware and a combination thereof. The above-mentioned modules can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.

[0124] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 8 As shown. The computer device includes a processor, a memory, a network interface and a database connected via a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store device record data. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, a method for identifying device anomalies based on APP application records is implemented.

[0125] Those skilled in the art will understand that Figure 8 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0126] In a third aspect, a computer device is provided. The computer device includes a memory and a processor. The memory stores a computer program. When the processor executes the computer program, the steps of any method in the above method embodiments are implemented.

[0127] In a fourth aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of any method in the above method embodiments are implemented.

[0128] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).

[0129] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0130] The above-mentioned embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the invention patent. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the attached claims.

Claims

1. A method for identifying device abnormalities based on APP application records, the method comprising: Obtaining device record data of a first preset number of mobile terminal devices on which the software application involved in the case is installed; wherein the device record data includes device application installation list data; Performing data processing on each of the device record data to obtain the corresponding processed device record data; Performing feature extraction processing on each of the processed device record data to obtain risk label feature data of the corresponding mobile terminal device; wherein the risk label feature data includes risk software application feature data, risk mobile terminal device feature data and risk wireless network feature data; The risk label feature data is input into a pre-trained device privacy risk abnormal location identification network model to obtain the location information of the corresponding device privacy risk abnormal location.

2. The method according to claim 1, characterized in that The performing data processing on each of the device record data to obtain the corresponding processed device record data includes: Performing data cleaning processing on each of the device record data to obtain the corresponding cleaned device record data; In response to performing a configuration operation on a data screening parameter, determining the data screening parameter; Data screening processing is performed on each of the cleaned device record data according to the data screening parameters to obtain the corresponding processed device record data.

3. The method according to claim 1, characterized in that: The method further comprises: Acquire a second preset number of historical tag feature data of the mobile terminal devices; wherein the historical tag feature data includes risky software application historical feature data, risky mobile terminal device historical feature data and risky wireless network historical feature data; Randomly divide the historical tag feature data to generate a training sample set and a test sample set; The preset initial network model for identifying abnormal locations of device privacy risk is trained according to the training sample set, and the initial network model for identifying abnormal locations of device privacy risk is tested according to the test sample set, and the model parameters of the initial network model for identifying abnormal locations of device privacy risk are adjusted based on the indicators obtained from training and testing until the indicators meet the preset requirements, and the network model for identifying abnormal locations of device privacy risk is generated, so as to output the location information of each of the abnormal locations of device privacy risk based on the network model for identifying abnormal locations of device privacy risk.

4. The method according to claim 1, characterized in that: The method comprises: Based on the Geohash algorithm, each of the position information is encoded to obtain a corresponding position information character string.

5. The method according to claim 4, characterized in that The method comprises: Based on a cluster analysis algorithm, cluster analysis is performed on each of the location information strings to obtain a high-density risk area; Performing statistical analysis on each of the position information according to the high-density risk area to obtain corresponding target position information; the target position information is the position information within the high-density risk area; Performing statistical analysis based on each of the target location information and the risk mobile terminal device characteristic data corresponding to the target location information to obtain the number of risk mobile terminals corresponding to the target location information; Determine the total number of terminals in the high-density risk area according to the sum of the numbers of each terminal; In response to the total number of terminals being greater than or equal to a total number threshold, the high-density risk area is determined as an abnormally concentrated area of ​​device privacy risks.

6. The method according to claim 5, characterized in that After the step of determining the high-density risk area as an abnormally concentrated area of ​​device privacy risks in response to the total number of terminals being greater than or equal to a total number threshold, the step further includes: Inputting the risk label feature data corresponding to each target location information into a pre-trained regional privacy risk assessment model to obtain a comprehensive regional privacy risk score for the device privacy risk abnormality clustering area; The regional privacy risk level is determined based on the comprehensive privacy risk score of the region.

7. The method according to claim 6, characterized in that The method further comprises: Determine the regional privacy risk statistics result according to the risky wireless network characteristic data corresponding to each target location information, the device privacy risk abnormal concentration area and the regional privacy risk level; the regional privacy risk statistics result includes the regional privacy risk level, the device privacy risk abnormal concentration area, the total number of terminals corresponding to the device privacy risk abnormal concentration area and the total number of risky wireless networks corresponding to the device privacy risk abnormal concentration area; The regional privacy risk statistical results are displayed on the regional privacy risk statistical results display interface.

8. A device for identifying device anomalies based on APP application records, characterized in that: The device comprises: A data acquisition module, used to acquire device record data of mobile terminal devices on which a first preset number of software applications involved in the case are installed; wherein the device record data includes device application installation list data; A data processing module, used for processing the recorded data of each device to obtain the corresponding processed recorded data of the device; A feature extraction module is used to perform feature extraction processing on each of the processed device record data to obtain risk label feature data of the corresponding mobile terminal device; wherein the risk label feature data includes risk software application feature data, risk mobile terminal device feature data and risk wireless network feature data; The location identification module is used to input the risk label feature data of each device into a pre-trained device privacy risk abnormal location identification network model to obtain the location information of the corresponding device privacy risk abnormal location.

9. A computer device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.