Client simulation positioning detection method and device, computer equipment and storage medium

By obtaining the historical positioning trajectory data and integrity detection of target applications of mobile terminal devices, the problem that traditional positioning methods are difficult to identify simulated positioning is solved, and the security and reliability of positioning services are improved.

CN120075742APending Publication Date: 2025-05-30BEIJING BAILONG MAYUN TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510180295.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-18
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Traditional mobile terminal positioning methods are difficult to fully identify various simulated positioning methods, resulting in poor security and reliability of positioning services.

Method used

By obtaining the historical positioning trajectory data of the target application within the preset time period, we judge whether there are abnormal positioning points, and conducting integrity detection on the target application to determine whether there are traces of tampered, thereby determining whether there are simulated positioning on the client.

Benefits of technology

The security and reliability of mobile terminal device positioning services are improved, and it is possible to determine more quickly and accurately whether the client has simulated positioning.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120075742A_ABST
    Figure CN120075742A_ABST
Patent Text Reader

Abstract

The invention relates to a client simulation positioning detection method and device, computer equipment and a storage medium. The method comprises the following steps: acquiring historical positioning track data of a target application of a client within a preset time period; judging whether an abnormal positioning point exists or not according to the historical positioning track data; in response to the existence of the abnormal positioning point, detecting the integrity of the target application, and judging whether the target application has a tampered trace or not; in response to the fact that the tampered trace does not exist in the target application, it is judged that the client does not have simulated positioning; and in response to the tampered trace in the target application, judging that the client has simulated positioning. By adopting the method, whether simulation positioning exists in the target application of the client can be quickly and accurately judged, so that the safety and the reliability of a positioning service based on the mobile terminal equipment are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of mobile terminal security, and particularly to a method and device for detecting client simulated positioning, a computer device, and a storage medium. Background Art

[0002] With the development of mobile terminal devices, positioning technologies applied to mobile terminal devices have emerged. While providing convenience to users, the positioning technologies also make the users' mobile terminal devices face the risk of being invaded by simulated positioning.

[0003] Traditional positioning methods applied to mobile terminal devices often have difficulty in comprehensively identifying various simulated positioning means, resulting in poor security and reliability of positioning services. Summary of the Invention

[0004] Based on this, in view of the above technical problems, it is necessary to provide a method and device for detecting client simulated positioning, a computer device, and a storage medium that can improve the security and reliability of positioning services applied to mobile terminal devices.

[0005] In a first aspect, a method for detecting client simulated positioning is provided. The method includes:

[0006] Obtain historical positioning trajectory data of a target application of a client within a preset time period;

[0007] Judge whether there are abnormal positioning points according to the historical positioning trajectory data;

[0008] In response to the existence of abnormal positioning points, detect the integrity of the target application and judge whether there are traces of tampering with the target application;

[0009] In response to the absence of traces of tampering in the target application, determine that there is no simulated positioning on the client;

[0010] In response to the existence of traces of tampering in the target application, determine that there is simulated positioning on the client.

[0011] In some embodiments, obtaining historical positioning trajectory data of a target application of a client within a preset time period includes:

[0012] Collect historical positioning trajectory data corresponding to the target application through a system positioning callback mechanism;

[0013] Judge whether the data volume of the collected historical positioning trajectory data meets the detection requirements;

[0014] In response to the data volume meeting the detection requirements, enter the step of judging whether there are abnormal positioning points according to the historical positioning trajectory data;

[0015] In response to the data volume not reaching the detection requirement, return the steps of collecting historical location trajectory data corresponding to the target application through the system positioning callback mechanism.

[0016] In some embodiments, determining whether there are abnormal positioning points based on the historical location trajectory data includes:

[0017] Performing time series analysis on the historical location trajectory data to identify the positioning points continuously distributed in time in the historical location trajectory data;

[0018] Detecting the distance change data between each positioning point;

[0019] Identifying whether there are positioning points with sudden location changes based on the distance change data;

[0020] In response to the existence of positioning points with sudden location changes, determining that there are abnormal positioning points in the target application; in response to the non-existence of positioning points with sudden location changes, determining that there are no abnormal positioning points in the target application.

[0021] In some embodiments, detecting the integrity of the target application includes:

[0022] Detecting whether the file path corresponding to the target application has been modified; and / or

[0023] Detecting whether the PMS object obtained by the target application for interacting with the system has been proxied; and / or

[0024] Detecting whether the target application is in a dual instance state; and / or

[0025] Detecting whether there are shared object files that do not belong to the target file itself in the directory corresponding to the target application.

[0026] In some embodiments, detecting whether the file path corresponding to the target application has been modified includes:

[0027] Obtaining the current installation path of the target application on the client and the target installation path provided by the official app store of the target application;

[0028] Comparing whether the current installation path is consistent with the target installation path;

[0029] In response to the current installation path being consistent with the target installation path, determining that the file path corresponding to the target application has not been modified; in response to the current installation path being inconsistent with the target installation path, determining that the file path corresponding to the target application has been modified.

[0030] In some embodiments, detecting whether the target application is in a dual instance state includes:

[0031] Obtaining the return value of the system API or file feature information;

[0032] In response to the return value of the system API being modified, or the file feature information not being consistent with the preset expected information, it is determined that the target application is in the dual - instance state;

[0033] In response to the return value of the system API not being modified and the file feature information being consistent with the preset expected information, it is determined that the target application is not in the dual - instance state.

[0034] In some embodiments, detecting whether there are shared object files that do not belong to the target file itself in the directory corresponding to the target application includes:

[0035] Scanning the private directory and / or sandbox directory corresponding to the target application to detect whether there are shared object files from unknown sources in the private directory and / or sandbox directory.

[0036] In a second aspect, a client - side simulated location detection device is provided. The device includes:

[0037] A historical location data acquisition module for acquiring historical location trajectory data of the target application of the client within a preset time period;

[0038] An abnormal location judgment module for judging whether there are abnormal location points according to the historical location trajectory data;

[0039] An integrity detection module for, in response to the existence of abnormal location points, detecting the integrity of the target application to judge whether there are traces of tampering with the target application;

[0040] A simulated location determination module for, in response to there being no traces of tampering in the target application, determining that there is no simulated location on the client; and, in response to there being traces of tampering in the target application, determining that there is simulated location on the client.

[0041] In a third aspect, a computer device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the steps of the client - side simulated location detection method according to any item of the first aspect are implemented.

[0042] In a fourth aspect, a computer - readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, the client - side simulated location detection method is implemented.

[0043] The above client-side simulated location detection method, device, computer device, and storage medium first collect historical location trajectory data of the target application. If an abnormal location point is identified in the historical location trajectory data, the integrity test of the target application can be further performed. Since there are more than one reason for the existence of the abnormal location point, it is necessary to distinguish whether it is a simulated location caused by human intervention or an abnormality caused by a signal deviation without human intervention. In the embodiments of the present application, based on the detection of the abnormal location point, the application integrity test is further combined, so as to more quickly and accurately determine whether there is a simulated location in the target application of the client, and thus can assist the mobile terminal device in detecting the simulated location, improving the security and reliability of the location service based on the mobile terminal device. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] Figure 1 is a schematic flowchart of the client-side simulated location detection method in some embodiments;

[0045] Figure 2 is a schematic flowchart of the steps of obtaining the historical location trajectory data of the target application of the client within a preset time period in some embodiments;

[0046] Figure 3 is a schematic flowchart of the steps of determining whether there is an abnormal location point according to the historical location trajectory data in some embodiments;

[0047] Figure 4 is a schematic flowchart of detecting the integrity of the target application in some application examples;

[0048] Figure 5 is a structural block diagram of the client-side simulated location detection device in some embodiments;

[0049] Figure 6 is an internal structure diagram of a computer device in some embodiments. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0050] In order to make the objectives, technical solutions, and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0051] The client-side simulated location detection method provided by the present application can be applied to a mobile terminal device. Among them, the mobile terminal device can be, but is not limited to, various personal computers, laptop computers, smart phones, tablet computers, and portable wearable devices, etc.

[0052] In some embodiments, such as Figure 1As shown, a client-side simulated location detection method is provided. Taking the application of this method to a mobile terminal device as an example, it includes the following steps:

[0053] Step S102: Obtain the historical location trajectory data of the target application on the client within a preset time period.

[0054] Among them, the preset time period refers to a specific time period before the current time point or target time point specified by the user. The target application refers to any one or more selected applications to be detected loaded on the client.

[0055] In this step, after the client-side simulated location detection is started, the mobile terminal device can obtain the application list on the client, select the application to be detected as the target application, and then collect the location data corresponding to N location operations of the target application within the preset time period as the historical location trajectory data of the target application; where N is a positive integer greater than 1.

[0056] Step S104: Determine whether there are abnormal location points based on the historical location trajectory data.

[0057] Among them, an abnormal location point refers to a location point with an abnormal position in the location trajectory formed by the historical location trajectory data. For example, it can be a location point with an abnormal mutation in position compared to the positions of the previous and subsequent location points.

[0058] In this step, a location point detection algorithm can be applied to detect whether the location trajectory formed by the historical location trajectory data is smoothly and continuously changing, and to detect whether there are location points with abnormal position mutations, etc., so as to determine whether there are abnormal location points. If so, go to step S106; if not, further go to step S112. Among them, step S112 is: In response to the absence of abnormal location points, determine that the location of the target application is normal.

[0059] Step S106: In response to the existence of abnormal location points, detect the integrity of the target application and determine whether there are traces of tampering with the target application.

[0060] In this step, if it is detected that there are abnormal location points, the process of detecting the integrity of the target application can be further started to determine whether there are traces of tampering with the target application. On the other hand, if no abnormal location points are detected, it can be explained that the location data of the target application is normal and there is no simulated location behavior.

[0061] Step S108: In response to the absence of traces of tampering in the target application, determine that there is no simulated location on the client.

[0062] In this step, if no traces of artificial malicious tampering are found in the target application after the application integrity detection, it can be determined that there is no simulated location on the client side, and the abnormal location points that appear in the historical location trajectory data may be anomalies caused by non-artificial factors. For example, it may be caused by weak or unstable GPS (Global Positioning System) signals.

[0063] Step S110: In response to the presence of tampering traces in the target application, determine that there is simulated location on the client side.

[0064] In this step, if traces of artificial malicious tampering are found in the target application after the application integrity detection, it means that the abnormal location points that appear in the historical location trajectory data are simulated locations caused by artificial intervention and normal positioning.

[0065] For the above client-side simulated location detection method, first, by collecting the historical location trajectory data of the target application, if abnormal location points are identified in the historical location trajectory data, the integrity test of the target application can be further performed. Since there is more than one reason for the existence of abnormal location points, it is necessary to distinguish whether it is a simulated location with artificial intervention or an anomaly caused by a signal deviation without artificial intervention. In the embodiments of the present application, on the basis of detecting abnormal location points, the application integrity test is further combined, so as to be able to more quickly and accurately determine whether there is simulated location in the target application of the client side, so as to be able to assist the mobile terminal device in detecting simulated location and improve the security and reliability of the location service based on the mobile terminal device.

[0066] In some embodiments, refer to Figure 2 as shown Figure 2 The flowchart shows the steps of obtaining the historical location trajectory data of the target application of the client side within a preset time period in some embodiments. Among them, obtaining the historical location trajectory data of the target application of the client side within a preset time period may include the following steps:

[0067] Step S202: Collect the historical location trajectory data corresponding to the target application through the system location callback mechanism.

[0068] Step S204: Determine whether the data volume of the collected historical location trajectory data meets the detection requirements.

[0069] In response to the data volume meeting the detection requirements, enter step S104: Determine whether there are abnormal location points according to the historical location trajectory data.

[0070] In response to the data volume not meeting the detection requirements, return to step S202: Collect the historical location trajectory data corresponding to the target application through the system location callback mechanism.

[0071] In this embodiment, during the operation of the target application on the client side of the mobile terminal device, when the location information of the mobile terminal device changes, through the system location callback mechanism, the system will call the corresponding callback function to notify the target application, so that the target application can respond to the device location change in real time and obtain the current device location information accordingly to implement the location service. Therefore, the historical location trajectory data corresponding to the target application can be collected through the system location callback mechanism, and before entering the step of detecting abnormal location points, it is judged whether the amount of the collected historical location trajectory data reaches the detection requirement.

[0072] This embodiment can improve the accuracy of subsequent detection, avoid the problem of inaccurate detection of abnormal location points caused by unreliable data sources or insufficient data volume, and thus improve the accuracy and reliability of simulated location judgment.

[0073] In some embodiments, as shown in Figure 3 shown, Figure 3 FIG. shows a schematic flow chart of steps for judging whether there are abnormal location points according to historical location trajectory data in some embodiments. Among them, judging whether there are abnormal location points according to historical location trajectory data may specifically include the following steps:

[0074] Step S302: Perform time series analysis on the historical location trajectory data to identify the location points continuously distributed in time in the historical location trajectory data;

[0075] Step S304: Detect the distance change data between each location point;

[0076] Step S306: Judge whether there are location points with sudden position changes according to the distance change data;

[0077] In response to the existence of location points with sudden position changes, enter step S308: Determine that there are abnormal location points in the target application; in response to the non-existence of location points with sudden position changes, enter step S309: Determine that there are no abnormal location points in the target application.

[0078] In this embodiment, by identifying the location points continuously distributed in time in the historical location trajectory data and detecting the distance changes between each location point continuously distributed in time, it is possible to accurately and quickly determine whether there are location points with non-smooth changes and sudden distance changes from the adjacent location points among the location points continuously distributed in time. Such location points are very likely to be abnormal location points.

[0079] In some embodiments, detecting the integrity of a target application includes: detecting whether the file path corresponding to the target application has been modified; and / or, detecting whether the PMS (Package Manager Service) object obtained by the target application for interacting with the system has been proxied; and / or, detecting whether the target application is in a dual-mode state; and / or, detecting whether there are shared object files that do not belong to the target file itself in the directory corresponding to the target application.

[0080] The above method for detecting the integrity of the target application can be executed alone or in combination. The detection can be performed in sequence or synchronously. As long as one of the scenarios is "yes", it can be determined that the target application or the system has been tampered with. If all detections are "no", it can be determined that there is no trace of tampering in the target application or the system. Then, combined with the detection results of the abnormal positioning points, a conclusion can be finally drawn on whether there is simulated positioning in the target application.

[0081] In this embodiment, the execution order of the above four methods for detecting the integrity of the target application can be evaluated according to aspects such as the cost of each method, the system resources consumed, and the time efficiency. The execution order of the integrity detection methods is sorted in ascending order of execution cost, increasing order of system resources consumed, and increasing order of execution time, so as to achieve the integrity detection of the target application with less cost, fewer system resources, and shorter time, thereby improving the efficiency of simulated positioning detection of the client.

[0082] In some embodiments, detecting whether the file path corresponding to the target application has been modified includes: obtaining the current installation path of the target application on the client and the target installation path provided by the official application store of the target application; comparing whether the current installation path is the same as the target installation path; in response to the current installation path being the same as the target installation path, determining that the file path corresponding to the target application has not been modified, and in response to the current installation path being different from the target installation path, determining that the file path corresponding to the target application has been modified.

[0083] In this embodiment, by comparing the current installation path of the target application on the client and the target installation path provided by the official application store of the target application, it is possible to quickly and accurately determine whether its corresponding file path has been modified. If the file path corresponding to the target application has been modified, it can indicate that there is a behavior of human intervention.

[0084] In some embodiments, detecting whether a target application is in a dual - instance state includes: obtaining the return value of a system API (Application Programming Interface) or file feature information; in response to the return value of the system API being modified, or the file feature information not being consistent with preset expected information, determining that the target application is in a dual - instance state; in response to the return value of the system API not being modified and the file feature information being consistent with the preset expected information, determining that the target application is not in a dual - instance state.

[0085] In this embodiment, if the target application runs in a dual - instance environment, some dual - instance applications may modify the return value of the system API to deceive the target application into thinking that it runs in a normal environment. Therefore, it is possible to determine whether the target application runs in a dual - instance environment by calling a specific system API and checking whether its return value is consistent with the expected value.

[0086] In some embodiments, detecting whether there is a shared object file that does not belong to the target file itself in the directory corresponding to the target application includes: scanning the private directory or sandbox directory corresponding to the target application to detect whether there is a shared object file from an unknown source in the private directory or sandbox directory.

[0087] In this embodiment, each Android application has its own private storage space, which can be a private directory and / or a sandbox directory. Among them, the sandbox directory is a mechanism in the operating system for isolating application data, ensuring that each application can only read and write data in its own sandbox and cannot directly access the data of other applications. This mechanism enhances the security and privacy of user data. In the Android system, an independent sandbox directory can also be provided for each application. By scanning the private directory or sandbox directory corresponding to the target application and detecting whether there is a shared object file from an unknown source (such as a so file or other executable files) in these directories, it is possible to quickly and accurately determine whether the target application has been tampered with or accessed by other programs of unknown origin.

[0088] In some application instances, refer to Figure 4 , Figure 4 shows a schematic flow chart for detecting the integrity of a target application in some application instances. In this application instance, a preferred execution order is shown. In other embodiments, it can also be adjusted according to requirements.

[0089] It should be understood that although Figures 1 to 4The steps in the flowchart are shown in sequence according to the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise clearly stated in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, Figures 1 to 4 At least some of the steps may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least some of the sub-steps or stages of other steps or other steps.

[0090] In some embodiments, as Figure 5 shown, a client-side simulated location detection device is provided, including: a historical location data acquisition module 510, an abnormal location judgment module 520, an integrity detection module 530, and a simulated location determination module 540, where:

[0091] The historical location data acquisition module 510 is used to acquire the historical location trajectory data of the target application of the client within a preset time period;

[0092] The abnormal location judgment module 520 is used to judge whether there are abnormal location points according to the historical location trajectory data;

[0093] The integrity detection module 530 is used to detect the integrity of the target application in response to the existence of abnormal location points, and judge whether there are traces of tampering with the target application;

[0094] The simulated location determination module 540 is used to determine that there is no simulated location of the client in response to the absence of traces of tampering in the target application; and, in response to the existence of traces of tampering in the target application, determine that there is simulated location of the client.

[0095] In some embodiments, the historical location data acquisition module 510 is further used to collect the historical location trajectory data corresponding to the target application through the system location callback mechanism; judge whether the data volume of the collected historical location trajectory data reaches the detection requirement; in response to the data volume reaching the detection requirement, enter the step of judging whether there are abnormal location points according to the historical location trajectory data; in response to the data volume not reaching the detection requirement, return to the step of collecting the historical location trajectory data corresponding to the target application through the system location callback mechanism.

[0096] In some embodiments, the abnormal location determination module 520 is further configured to perform time series analysis on historical location trajectory data, identify location points continuously distributed in time in the historical location trajectory data; detect distance change data between location points; identify whether there are location points with position mutations according to the distance change data; in response to the existence of location points with position mutations, determine that there are abnormal location points in the target application, and in response to the non-existence of location points with position mutations, determine that there are no abnormal location points in the target application.

[0097] In some embodiments, the integrity detection module 530 is further configured to detect whether the file path corresponding to the target application is modified; and / or detect whether the PMS object obtained by the target application for interacting with the system is proxied; and / or detect whether the target application is in a dual instance state; and / or detect whether there are shared object files that do not belong to the target file itself in the directory corresponding to the target application.

[0098] In some embodiments, the integrity detection module 530 is further configured to obtain the current installation path of the target application on the client and the target installation path provided by the official app store of the target application; compare whether the current installation path is consistent with the target installation path; in response to the current installation path being consistent with the target installation path, determine that the file path corresponding to the target application has not been modified, and in response to the current installation path being inconsistent with the target installation path, determine that the file path corresponding to the target application has been modified.

[0099] In some embodiments, the integrity detection module 530 is further configured to obtain the return value of the system API or file feature information; in response to the return value of the system API being modified, or the file feature information being inconsistent with the preset expected information, determine that the target application is in a dual instance state; in response to the return value of the system API not being modified and the file feature information being consistent with the preset expected information, determine that the target application is not in a dual instance state.

[0100] In some embodiments, the integrity detection module 530 is further configured to scan the private directory and / or sandbox directory corresponding to the target application to detect whether there are shared object files from unknown sources in the private directory and / or sandbox directory.

[0101] For the specific limitations of the client-side simulated location detection device, reference may be made to the limitations on the client-side simulated location detection method described above, which will not be elaborated here. Each module in the above client-side simulated location detection device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the computer device in hardware form or be independent of it, or be stored in the memory of the computer device in software form, so as to facilitate the processor to call and execute the operations corresponding to the above modules.

[0102] In some embodiments, a computer device is provided. The computer device may be a terminal, and its internal structural diagram may be as shown in Figure 6 . The computer device includes a processor, a memory, a network interface, a display screen, and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a method for detecting client simulated positioning. The display screen of the computer device may be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device may be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the housing of the computer device, or an external keyboard, touchpad, or mouse, etc.

[0103] Those skilled in the art can understand that Figure 6 the structure shown in is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0104] In some embodiments, a computer device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented: obtaining historical positioning trajectory data of a target application of a client within a preset time period; judging whether there are abnormal positioning points according to the historical positioning trajectory data; in response to the existence of abnormal positioning points, detecting the integrity of the target application to judge whether there are traces of tampering with the target application; in response to the non-existence of traces of tampering in the target application, determining that the client does not have simulated positioning; in response to the existence of traces of tampering in the target application, determining that the client has simulated positioning.

[0105] In some embodiments, when the processor executes the computer program, the following steps are further implemented: collecting historical positioning trajectory data corresponding to the target application through a system positioning callback mechanism; judging whether the data volume of the collected historical positioning trajectory data reaches the detection requirement; in response to the data volume reaching the detection requirement, entering the step of judging whether there are abnormal positioning points according to the historical positioning trajectory data; in response to the data volume not reaching the detection requirement, returning to the step of collecting historical positioning trajectory data corresponding to the target application through the system positioning callback mechanism.

[0106] In some embodiments, when the processor executes a computer program, the following steps are further implemented: performing time series analysis on historical positioning trajectory data to identify positioning points continuously distributed in time in the historical positioning trajectory data; detecting distance change data between the positioning points; identifying whether there are positioning points with position mutations according to the distance change data; in response to the existence of positioning points with position mutations, determining that there are abnormal positioning points in the target application, and in response to the non-existence of positioning points with position mutations, determining that there are no abnormal positioning points in the target application.

[0107] In some embodiments, when the processor executes a computer program, the following steps are further implemented: detecting whether the file path corresponding to the target application is modified; and / or detecting whether the PMS object obtained by the target application for interacting with the system is proxied; and / or detecting whether the target application is in a dual instance state; and / or detecting whether there are shared object files that do not belong to the target file itself in the directory corresponding to the target application.

[0108] In some embodiments, when the processor executes a computer program, the following steps are further implemented: obtaining the current installation path of the target application on the client and the target installation path provided by the official application store of the target application; comparing whether the current installation path is consistent with the target installation path; in response to the current installation path being consistent with the target installation path, determining that the file path corresponding to the target application has not been modified, and in response to the current installation path being inconsistent with the target installation path, determining that the file path corresponding to the target application has been modified.

[0109] In some embodiments, when the processor executes a computer program, the following steps are further implemented: obtaining the return value of the system API or file feature information; in response to the return value of the system API being modified, or the file feature information being inconsistent with the preset expected information, determining that the target application is in a dual instance state; in response to the return value of the system API not being modified and the file feature information being consistent with the preset expected information, determining that the target application is not in a dual instance state.

[0110] In some embodiments, when the processor executes a computer program, the following steps are further implemented: scanning the private directory and / or sandbox directory corresponding to the target application to detect whether there are shared object files from unknown sources in the private directory and / or sandbox directory.

[0111] In some embodiments, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented: obtaining historical positioning trajectory data of a target application of a client within a preset time period; determining whether there are abnormal positioning points according to the historical positioning trajectory data; in response to the existence of abnormal positioning points, detecting the integrity of the target application to determine whether there are traces of tampering in the target application; in response to the absence of traces of tampering in the target application, determining that there is no simulated positioning on the client; in response to the existence of traces of tampering in the target application, determining that there is simulated positioning on the client.

[0112] In some embodiments, when the computer program is executed by a processor, the following steps are further implemented: collecting historical positioning trajectory data corresponding to the target application through a system positioning callback mechanism; determining whether the amount of the collected historical positioning trajectory data reaches the detection requirement; in response to the amount of data reaching the detection requirement, entering the step of determining whether there are abnormal positioning points according to the historical positioning trajectory data; in response to the amount of data not reaching the detection requirement, returning to the step of collecting historical positioning trajectory data corresponding to the target application through the system positioning callback mechanism.

[0113] In some embodiments, when the computer program is executed by a processor, the following steps are further implemented: performing time series analysis on the historical positioning trajectory data to identify the positioning points continuously distributed in time in the historical positioning trajectory data; detecting the distance change data between the positioning points; identifying whether there are positioning points with sudden position changes according to the distance change data; in response to the existence of positioning points with sudden position changes, determining that there are abnormal positioning points in the target application, and in response to the absence of positioning points with sudden position changes, determining that there are no abnormal positioning points in the target application.

[0114] In some embodiments, when the computer program is executed by a processor, the following steps are further implemented: detecting whether the file path corresponding to the target application is modified; and / or detecting whether the PMS object obtained by the target application for interacting with the system is proxied; and / or detecting whether the target application is in a dual-mode state; and / or detecting whether there are shared object files that do not belong to the target file itself in the directory corresponding to the target application.

[0115] In some embodiments, when the computer program is executed by a processor, the following steps are further implemented: obtaining the current installation path of the target application on the client and the target installation path provided by the official application store of the target application; comparing whether the current installation path is consistent with the target installation path; in response to the current installation path being consistent with the target installation path, determining that the file path corresponding to the target application has not been modified, and in response to the current installation path being inconsistent with the target installation path, determining that the file path corresponding to the target application has been modified.

[0116] In some embodiments, when the computer program is executed by a processor, the following steps are further implemented: obtaining the return value of the system API or file feature information; determining that the target application is in a split state in response to the return value of the system API being modified or the file feature information not being consistent with the preset expected information; and determining that the target application is not in a split state in response to the return value of the system API not being modified and the file feature information being consistent with the preset expected information.

[0117] In some embodiments, when the computer program is executed by a processor, the following steps are further implemented: scanning the private directory and / or sandbox directory corresponding to the target application to detect whether there is a shared object file from an unknown source in the private directory and / or sandbox directory.

[0118] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0119] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0120] In addition, the term "and / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the characters in this article generally represent that the associated objects before and after are in an "or" relationship.

[0121] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the appended claims.

[0122] It should be noted that in the embodiments of the present application, for relevant data such as user information or user data (for example, historical positioning track data), it is necessary to obtain the authorization and consent of the user before acquisition and processing. When the embodiments of the present application are applied to specific products or technologies, it is necessary to obtain the permission or consent of the user, and the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions.

Claims

1. A client simulation positioning detection method, the method comprising: Obtain historical positioning trajectory data of the target application of the client within a preset time period; Determine whether there is an abnormal positioning point according to the historical positioning trajectory data; In response to the existence of the abnormal positioning point, the integrity of the target application is detected to determine whether the target application has traces of tampering; In response to the target application not having any tampering trace, determining that the client does not have simulated positioning; In response to the existence of tampering traces in the target application, it is determined that the client has simulated positioning.

2. The method according to claim 1, characterized in that The step of obtaining historical positioning trajectory data of a target application of a client within a preset time period includes: Collect the historical positioning trajectory data corresponding to the target application through the system positioning callback mechanism; Determine whether the amount of the collected historical positioning trajectory data meets the detection requirements; In response to the data volume reaching the detection requirement, entering the step of determining whether there is an abnormal positioning point according to the historical positioning trajectory data; In response to the data volume not meeting the detection requirement, returning to the step of collecting historical positioning trajectory data corresponding to the target application through the system positioning callback mechanism.

3. The method according to claim 1, characterized in that The determining whether there is an abnormal positioning point according to the historical positioning trajectory data includes: Performing time series analysis on the historical positioning trajectory data to identify positioning points in the historical positioning trajectory data that are continuously distributed in time; Detecting distance change data between each of the positioning points; Identify whether there is a positioning point with a sudden position change according to the distance change data; In response to the presence of a positioning point with a sudden change in position, it is determined that there is an abnormal positioning point in the target application, and in response to the absence of a positioning point with a sudden change in position, it is determined that there is no abnormal positioning point in the target application.

4. The method according to claim 1, characterized in that: The detecting the integrity of the target application includes: Detecting whether the file path corresponding to the target application is modified; and / or Detecting whether the PMS object acquired by the target application for interacting with the system is proxied; and / or Detecting whether the target application is in a clone state; and / or Check whether there is a shared object file that does not belong to the target file itself in the directory corresponding to the target application.

5. The method according to claim 4, characterized in that The detecting whether the file path corresponding to the target application is modified includes: Obtaining a current installation path of the target application on the client and a target installation path provided by an official application store of the target application; Comparing the current installation path with the target installation path to see if they are consistent; In response to the current installation path being consistent with the target installation path, it is determined that the file path corresponding to the target application has not been modified. In response to the current installation path being inconsistent with the target installation path, it is determined that the file path corresponding to the target application has been modified.

6. The method according to claim 4, characterized in that The detecting whether the target application is in a clone state includes: Get the return value of the system API or file feature information; In response to the return value of the system API being modified, or the file characteristic information being inconsistent with preset expected information, determining that the target application is in a clone state; In response to the return value of the system API not being modified and the file characteristic information being consistent with preset expected information, it is determined that the target application is not in a clone state.

7. The method according to claim 4, characterized in that The detecting whether there is a shared object file that does not belong to the target file itself in the directory corresponding to the target application includes: Scan the private directory and / or the sandbox directory corresponding to the target application to detect whether there are shared object files of unknown sources in the private directory and / or the sandbox directory.

8. A client simulation positioning detection device, characterized in that: The device comprises: A historical positioning data acquisition module is used to obtain the historical positioning trajectory data of the target application of the client within a preset time period; An abnormal positioning judgment module is used to judge whether there is an abnormal positioning point according to the historical positioning trajectory data; an integrity detection module, configured to detect the integrity of the target application in response to the presence of the abnormal positioning point, and determine whether the target application has any trace of tampering; The simulation positioning determination module is used to determine that the client does not have simulation positioning in response to the absence of tampering traces in the target application; and to determine that the client has simulation positioning in response to the presence of tampering traces in the target application.

9. A computer device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.