Method and device for detecting third-party library of mobile application based on static taint analysis

Through the method of static stain analysis and privacy policy consistency verification of mobile application third-party libraries, the problem of high complexity and insufficient accuracy of privacy compliance detection of mobile application third-party libraries is solved, and higher detection accuracy and applicability are achieved.

CN120180486APending Publication Date: 2025-06-20WUHAN HONGXIN TECH SERVICE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510136686.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-07
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

The prior art has problems of high complexity and insufficient accuracy in the privacy compliance analysis and detection of third-party libraries of mobile applications.

Method used

The detection method based on static taint analysis is adopted, and the third-party library of mobile applications is preprocessed, encapsulated into APK files, and privacy behavior is detected using static taint analysis tools, and consistently verified with the privacy policies of the third-party library to determine privacy compliance.

Benefits of technology

It improves the accuracy and applicability of privacy compliance detection of third-party libraries of mobile applications, and solves the problems of high detection complexity and insufficient accuracy in the prior art.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120180486A_ABST
    Figure CN120180486A_ABST
Patent Text Reader

Abstract

The invention discloses a detection method and device for a mobile application third-party library based on static taint analysis, and the method comprises the steps: carrying out the preprocessing of the mobile application third-party library, and packaging the mobile application third-party library into an APK file containing the third-party library; converting the privacy behavior into a taint analysis detection rule in a function signature form, performing static taint analysis on the packaged APK file containing the third-party library based on the privacy behavior detection rule by utilizing a static taint analysis tool, and detecting whether the APK file has a risk privacy behavior or not; extracting a behavior declared in the privacy policy of the third-party library of the mobile application, and performing consistency verification on the declared behavior and the detected risk privacy behavior of the third-party library of the mobile application; and determining a privacy compliance judgment result of the third-party library of the mobile application under the condition that a privacy behavior which is not declared or exceeds a declared range in the privacy policy of the third-party library of the mobile application appears.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of mobile application detection, and more specifically, to a method and device for detecting third-party libraries of mobile applications based on static taint analysis. Background Art

[0002] With the rapid development of the mobile Internet, developers are increasingly inclined to use third-party libraries to improve the development efficiency of APPs and bring a better experience to users. Surveys show that approximately 57% of application programs contain third-party advertising libraries, and more than 60% of the code in Android applications belongs to third-party libraries.

[0003] However, there are many privacy and security issues in current mobile application third-party libraries. For example, an analytics library may be used by multiple application programs to collect users' behavioral data to improve the user experience, but the analytics library may collect unique device information that identifies users. These identification information can be used to associate the information collected by the analytics library from different application programs to obtain a more comprehensive record of user activities, thus leading to a serious risk of personal privacy leakage.

[0004] Currently, the relevant privacy compliance analysis and detection of mobile application third-party libraries are mainly based on dynamic analysis, but it has certain limitations. The dynamic analysis of mobile application third-party libraries needs to rely on the application program containing the third-party library and provide the corresponding runtime environment. This not only requires accurate identification of the third-party libraries contained in the application program, but also requires distinguishing between application code and third-party library code, and there are deficiencies such as limited code coverage, dependence on specific inputs during detection, and complex environment deployment. Summary of the Invention

[0005] Aiming at at least one defect or improvement requirement of the prior art, the present invention provides a method and device for detecting third-party libraries of mobile applications based on static taint analysis, which solves the problems of high complexity and insufficient accuracy in the relevant privacy compliance analysis and detection of mobile application third-party libraries, and improves the accuracy and applicability of privacy compliance detection of mobile application third-party libraries.

[0006] To achieve the above object, according to the first aspect of the present invention, a detection method for a third-party library of a mobile application based on static taint analysis is provided. The method includes: preprocessing the third-party library of the mobile application and encapsulating the third-party library of the mobile application into an APK file containing the third-party library; converting the privacy behavior into a taint analysis detection rule in the form of a function signature, and using a static taint analysis tool to perform static taint analysis on the encapsulated APK file containing the third-party library based on the privacy behavior detection rule to detect whether there is a risky privacy behavior in the APK file; extracting the behaviors declared in the privacy policy of the third-party library of the mobile application, and performing consistency verification on the declared behaviors and the detected risky privacy behaviors of the third-party library of the mobile application; in the case where there is a privacy behavior not declared or beyond the declared scope in the privacy policy of the third-party library of the mobile application, determining the privacy compliance determination result of the third-party library of the mobile application.

[0007] In an exemplary embodiment, the preprocessing the third-party library of the mobile application and encapsulating the third-party library of the mobile application into an APK file containing the third-party library includes: creating an Android engineering project and completing the basic configurations required for the Android engineering project; importing the source files of the third-party library of the mobile application into the Android engineering project; automatically building the project to generate an APK file encapsulated by the third-party library of the mobile application.

[0008] In an exemplary embodiment, the converting the privacy behavior into a taint analysis detection rule in the form of a function signature, and using a static taint analysis tool to perform static taint analysis on the encapsulated APK file containing the third-party library based on the privacy behavior detection rule to detect whether there is a risky privacy behavior in the APK file includes: constructing a privacy behavior rule set for taint analysis, where the privacy behavior rule set includes taint sources and taint sinks. Among them, the taint sources include application information, device information, location information, multimedia information, network information, personal identity information, and contact and calendar information, and the taint sinks include network transmission, file storage, log record, database storage, Bluetooth / NFC transmission, and SMS / MMS transmission; manually annotating the manifestation types for the taint sources and the taint sinks in the privacy behavior rule set, where the manifestation type is the way in which the taint sources and the taint sinks obtain or leak privacy in taint analysis.

[0009] In an exemplary embodiment, after the stain source and the stain convergence in the privacy behavior rule set are manually annotated with performance types, the method further includes: parsing the stain source and the stain convergence using regular matching to obtain a parsing result; converting the parsing result into the stain analysis detection rule according to the requirements of the static stain analysis tool, where the stain analysis detection rule is in JSON format and determines the stain source and the stain convergence in the form of a function signature.

[0010] In an exemplary embodiment, the method for using a static stain analysis tool to perform static stain analysis on an encapsulated APK file containing a third-party library based on a privacy behavior detection rule to detect whether there are risky privacy behaviors in the APK file includes: importing a standardized rule file from a detection rule specification module, constructing a privacy behavior model, parsing the encapsulated third-party library file from a data set preprocessing module to obtain basic information; completing the basic configuration of the static stain analysis tool according to the basic information and creating a new directory for storing privacy behavior detection results; detecting and outputting results for privacy behaviors existing in the third-party library of the mobile application based on the static stain analysis tool; performing statistical analysis on the output results according to the categories of the stain source and the stain convergence to generate privacy behavior detection results.

[0011] In an exemplary embodiment, after performing statistical analysis on the output results according to the categories of the stain source and the stain convergence to generate privacy behavior detection results, the method further includes: receiving the privacy behavior detection results from a privacy behavior detection module and obtaining the privacy policy corresponding to the third-party library of the mobile application; parsing the privacy behavior detection results and the privacy policy to obtain the privacy types involved in the privacy behavior detection results, and searching for corresponding privacy handling statements from the privacy policy; comparing the actual handling methods and privacy handling statement methods of the same privacy type in the privacy behavior detection results and the privacy policy to determine the privacy compliance of the third-party library of the mobile application and record the privacy violation behaviors of the third-party library of the mobile application.

[0012] According to the second aspect of the present invention, there is also provided a detection device for a third-party library of a mobile application based on static taint analysis, which includes: a preprocessing unit for preprocessing the third-party library of the mobile application and encapsulating the third-party library of the mobile application into an APK file containing the third-party library; an analysis unit for converting a privacy behavior into a taint analysis detection rule in the form of a function signature, and performing static taint analysis on the encapsulated APK file containing the third-party library based on the privacy behavior detection rule by using a static taint analysis tool to detect whether there are risky privacy behaviors in the APK file; a verification unit for extracting the behaviors declared in the privacy policy of the third-party library of the mobile application and performing consistency verification between the declared behaviors and the detected risky privacy behaviors of the third-party library of the mobile application; a determination unit for determining the privacy compliance determination result of the third-party library of the mobile application in the case where there are privacy behaviors not declared or exceeding the declared scope in the privacy policy of the third-party library of the mobile application.

[0013] According to the third aspect of the present invention, there is also provided a computer-readable storage medium, in which a computer program is stored, and wherein the computer program is configured to execute the above-mentioned detection method for a third-party library of a mobile application based on static taint analysis when running.

[0014] According to the fourth aspect of the present invention, there is also provided an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the above-mentioned processor executes the above-mentioned detection method for a third-party library of a mobile application based on static taint analysis through the computer program.

[0015] Generally speaking, compared with the prior art by the above technical solution conceived by the present invention, the following beneficial effects can be achieved:

[0016] The present invention provides a detection method for a third-party library of a mobile application based on static taint analysis, which can preprocess the third-party library and directly encapsulate it into an APK file containing the third-party library, so that a static taint analysis tool can be directly used to test the privacy behaviors of the encapsulated third-party library to detect the risky privacy behaviors existing in the third-party library and perform consistency analysis with its privacy policy, and finally realize the privacy compliance detection of the third-party library, solving the problems of high complexity and insufficient accuracy in the relevant privacy compliance analysis and detection of the third-party library of the mobile application, and improving the accuracy and applicability of the privacy compliance detection of the third-party library of the mobile application. Description of the Drawings

[0017] To more clearly illustrate the technical solutions in the embodiments of the present application, the accompanying drawings required for the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0018] Figure 1 It is a schematic flowchart of an optional detection method for third-party libraries of mobile applications based on static taint analysis provided by the embodiments of the present application;

[0019] Figure 2 It is a general block diagram of an optional privacy compliance detection solution for third-party libraries of mobile applications provided by the embodiments of the present application;

[0020] Figure 3 It is a schematic flowchart of an optional preprocessing process for third-party libraries provided by the embodiments of the present application;

[0021] Figure 4 It is a schematic flowchart of an optional detection rule specification provided by the embodiments of the present application;

[0022] Figure 5 It is a schematic flowchart of an optional privacy compliance determination provided by the embodiments of the present application;

[0023] Figure 6 It is a schematic structural diagram of an optional detection device for third-party libraries of mobile applications based on static taint analysis provided by the embodiments of the present application;

[0024] Figure 7 It is a schematic structural diagram of an optional electronic device provided by the embodiments of the present application. Detailed implementation manners

[0025] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.

[0026] In the description, claims, and above-mentioned drawings of this application, the terms "first", "second", "third", etc. are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but optionally further includes steps or units not listed, or optionally further includes other steps or units inherent to these processes, methods, products, or devices.

[0027] According to one aspect of the embodiments of the present application, a detection method for third-party libraries of mobile applications based on static taint analysis is provided. The following combines Figure 1 to describe the detection method for third-party libraries of mobile applications based on static taint analysis provided by the embodiments of the present application.

[0028] Figure 1 is a schematic flowchart of an optional detection method for third-party libraries of mobile applications based on static taint analysis provided by the embodiments of the present application. As Figure 1 shown, the process of this method may include the following steps:

[0029] S102, preprocess the third-party libraries of mobile applications, and encapsulate the third-party libraries of mobile applications into an APK file containing the third-party libraries;

[0030] S104, convert the privacy behavior into a taint analysis detection rule in the form of a function signature, and use a static taint analysis tool to perform static taint analysis on the encapsulated APK file containing the third-party libraries based on the privacy behavior detection rule to detect whether there are risky privacy behaviors in the APK file;

[0031] S106, extract the behaviors declared in the privacy policy of the third-party libraries of mobile applications, and perform consistency verification between the declared behaviors and the detected risky privacy behaviors of the third-party libraries of mobile applications;

[0032] S108, in the case of privacy behaviors not declared or exceeding the declared scope in the privacy policy of the third-party libraries of mobile applications, determine the privacy compliance determination result of the third-party libraries of mobile applications.

[0033] A detection method for third-party libraries of mobile applications based on static taint analysis provided by the embodiments of the present application can obtain its risky privacy behaviors through static taint analysis of the third-party libraries encapsulated as APK files, and then perform consistency verification with the declarations in its privacy policy, so as to be able to discover privacy leakage problems existing in the third-party libraries of mobile applications and determine their privacy compliance.

[0034] It should be noted that a third - party library for mobile applications refers to a code library designed for mobile applications, developed and maintained by third - party developers or organizations. It usually contains reusable code, classes, methods, and functions, as well as other resources used in the application. Different from the libraries built into the Android operating system, they are generally used to extend the functionality and performance of the application, which can help mobile application developers efficiently implement various functions, such as network requests, data storage, and user interface design, thereby reducing the development difficulty and improving the development efficiency. Mobile third - party libraries are usually provided in the form of binary files, such as *.aar or *.jar files.

[0035] The static analysis technology adopted in this application is a technology for analyzing program code without executing the application. It usually discovers potential security vulnerabilities and data leakage problems by analyzing source code or binary code. Further, the static taint analysis technology is a type of static analysis technology. It analyzes the application by tracing the flow path of target sensitive data from the taint source to the taint sink. When the marked taint data is transmitted to an insecure function, it can be determined that there are potential security vulnerabilities or data leakage problems in the code. The taint source generally refers to the privacy information that can be obtained on the mobile device (including: location information, device unique identifier IMEI, contact information, etc.), and the taint sink generally refers to the methods and channels that may cause privacy information leakage (including: network transmission, file storage, logging, etc.).

[0036] Optionally, as Figure 2 shown, the third - party library for mobile applications can be pre - processed and directly packaged into an Android application package (APK) file containing the third - party library. This file refers to the application installation file format on the Android operating system. The APK file contains the application's code, resource files, and other necessary metadata. It is the packaged form of the application before installation. Users can deploy the application to an Android device by downloading and installing the APK file. Furthermore, the abstract privacy behavior can be embodied as a taint analysis detection rule in the form of a function signature, and the static taint analysis of the packaged third - party library can be carried out using a taint analysis tool based on the privacy behavior detection rule to detect its potentially risky privacy behavior. Finally, the behaviors declared in the third - party library's privacy policy are extracted and consistency verification is performed with the detected risky privacy behaviors of the third - party library. When there are privacy behaviors not declared or beyond the declared scope in the privacy policy, the privacy violation behavior of the third - party library can be discovered and its privacy compliance can be determined.

[0037] Through the above steps S102 to S108, by preprocessing the third-party libraries of mobile applications, the third-party libraries of mobile applications are encapsulated into APK files containing the third-party libraries; the privacy behaviors are converted into taint analysis detection rules in the form of function signatures, and the static taint analysis tool is used to perform static taint analysis on the encapsulated APK files containing the third-party libraries based on the privacy behavior detection rules to detect whether there are risky privacy behaviors in the APK files; extract the behaviors declared in the privacy policies of the third-party libraries of mobile applications, and perform consistency verification on the declared behaviors and the detected risky privacy behaviors of the third-party libraries of mobile applications; in the case of privacy behaviors not declared or exceeding the declared scope in the privacy policies of the third-party libraries of mobile applications, determine the privacy compliance determination results of the third-party libraries of mobile applications, solving the problems of high complexity and insufficient accuracy in the relevant privacy compliance analysis and detection of the third-party libraries of mobile applications, and improving the accuracy and applicability of the privacy compliance detection of the third-party libraries of mobile applications.

[0038] In an exemplary embodiment, preprocessing the third-party libraries of mobile applications and encapsulating the third-party libraries of mobile applications into APK files containing the third-party libraries includes:

[0039] S11, create an Android project and complete the basic configurations required for the Android project;

[0040] S12, import the source files of the third-party libraries of mobile applications into the Android project;

[0041] S13, automatically build the project to generate an APK file encapsulated by the third-party libraries of mobile applications.

[0042] In this embodiment, as Figure 3 shown, the third-party library preprocessing module is mainly used to encapsulate third-party libraries in aar and jar formats into apk files to implement the packaging and testing of third-party libraries. Here, AAR (Android Archive) and JAR (Java Archive) are two common file formats used to package and share code libraries in software development. AAR is a file format specific to the Android platform and is used to package and distribute Android application modules. It contains the code, resource files, dependent libraries, and other necessary metadata of the application module. JAR is a general Java file format used to package and distribute the code and resources of Java programs. A JAR file can contain Java classes, resource files, library files, and other relevant metadata.

[0043] Optionally, the preprocessing process may include: creating an Android project using Android Studio and completing the basic configurations required for the project, where unified default configurations are adopted. Then, the source files (*.aar and *.jar) of the third-party libraries need to be imported into the Android project, including copying the source files to the / app / libs directory of the project and adding dependencies on the corresponding third-party libraries in the / app / libs directory in the project build configuration file / app / build.gradle. Finally, use the method provided by Gradle to automatically build the project and generate an Apk file encapsulated by the third-party libraries.

[0044] It should be noted that Android Studio is an integrated development environment (IDE) developed by Google, specifically for developing Android applications. As the main tool for Android development, it provides rich functions and tools, aiming to simplify the application development process and improve the productivity of developers. Gradle is a project build tool used for automating the building, testing, and deployment of software projects. It supports multiple programming languages and technology stacks, such as Java, Kotlin, Groovy, Android, etc., and has a powerful plugin mechanism and a flexible build script language DSL. The main features of Gradle include declarative build scripts, highly customizable, efficient building, easy integration, and Android support, etc. In the software development process, using Gradle can improve the build speed and efficiency, simplify the build process, and improve the development efficiency.

[0045] In an exemplary embodiment, convert the privacy behaviors into taint analysis detection rules in the form of function signatures, and use a taint analysis tool to perform static taint analysis on the encapsulated APK file containing third-party libraries based on the privacy behavior detection rules. The privacy behaviors for detecting whether the APK file has risks include:

[0046] S21, construct a privacy behavior rule set for taint analysis. The privacy behavior rule set includes taint sources and taint sinks. Among them, the taint sources include application information, device information, location information, multimedia information, network information, personal identity information, and contact and calendar information. The taint sinks include network transmission, file storage, logging, database storage, Bluetooth / NFC transmission, and SMS / MMS transmission;

[0047] S22, manually label the manifestation types for the taint sources and taint sinks in the privacy behavior rule set. The manifestation type is the way in which the taint sources and taint sinks obtain or leak privacy in taint analysis.

[0048] In this embodiment, as Figure 4As shown in the figure, the detection rule specification module can be used to concretize abstract privacy behaviors into taint analysis detection rules in the form of function signatures, realizing the transformation from a rule set to a rule file. The process can include: constructing a privacy behavior rule set for taint analysis based on the taint analysis rules used in previous related work and referring to Android development documents. The taint sources are classified as: application information, device information, location information, multimedia information, network information, personal identity information, and contact and calendar information. The taint sinks are classified as: network transmission, file storage, logging, database storage, SharedPreferences storage, Bluetooth / NFC transmission, and SMS / MMS transmission. SharedPreferences is a lightweight persistent storage mechanism on the Android platform. It stores data in the form of key-value pairs and provides a simple API for applications to read and write data.

[0049] Furthermore, the manifestation types can be manually labeled for the source and sink in the rule set. The manifestation type refers to the way in which the source and sink obtain or leak privacy in taint analysis. The manifestation types of the source generally include: function return value, fields of an object, constant string. The manifestation types of the sink generally include: a certain parameter of a function, this pointer.

[0050] In an exemplary embodiment, after manually labeling the manifestation types for the taint sources and taint sinks in the privacy behavior rule set, the above method further includes:

[0051] S31, using regular expression matching to parse the taint sources and taint sinks to obtain a parsing result;

[0052] S32, converting the parsing result into a taint analysis detection rule according to the requirements of the static taint analysis tool. Among them, the taint analysis detection rule adopts the JSON format and determines the taint source and taint sink in the form of a function signature.

[0053] In this embodiment, regular expression matching can be used to parse the source and sink. For example, for a function, the function class name, function name, function return type, and parameter type list need to be parsed out. For a field, the class name, type, and name need to be parsed out.

[0054] After the parsing is completed, it can be converted into an analysis rule in a standardized rule file according to the requirements of the static taint analysis tool. Generally speaking, the rule file of taint analysis adopts the JSON format and determines the taint source source and taint sink sink in the form of a function signature. And JSON (JavaScript Object Notation) is a lightweight data exchange format, often used for data serialization, storage, and transmission. It uses a concise and easy-to-read text format to represent structured data.

[0055] In an exemplary embodiment, a static taint analysis tool is used to perform static taint analysis on the packaged APK file containing a third-party library based on privacy behavior detection rules. The privacy behaviors for detecting whether the APK file has risks include:

[0056] S41, import the standardized rule file from the detection rule specification module, construct a privacy behavior model, and parse the packaged third-party library file from the data set preprocessing module to obtain basic information;

[0057] S42, complete the basic configuration of the static taint analysis tool according to the basic information, and create a new directory for storing the privacy behavior detection results;

[0058] S43, based on the static taint analysis tool, detect the privacy behaviors existing in the third-party library of the mobile application and output the results;

[0059] S44, perform statistical analysis on the output results according to the categories of taint sources and taint convergences to generate privacy behavior detection results.

[0060] In this embodiment, the privacy behavior detection module can be used to detect the privacy behaviors of the packaged third-party library using a static taint analysis tool. Its process can include: importing the standardized rule file from the detection rule specification module, constructing a privacy behavior model <source, sink>, that is, the path from source to sink. Parsing the packaged third-party library file (apk) from the data set preprocessing module to obtain its basic relevant information (storage path, name, version number, etc.). Completing the basic configuration of the static taint analysis tool according to the basic information, and creating a new directory for storing the privacy behavior detection results. Based on the method provided by the static taint analysis tool, detecting the privacy behaviors existing in the third-party library. Performing statistical analysis on the output results according to the categories of source and sink to generate privacy behavior detection results.

[0061] In an exemplary embodiment, after performing statistical analysis on the output results according to the categories of taint sources and taint convergences to generate privacy behavior detection results, the above method further includes:

[0062] S51, receive the privacy behavior detection results from the privacy behavior detection module, and obtain the privacy policy corresponding to the third-party library of the mobile application;

[0063] S52, parse the privacy behavior detection results and the privacy policy, obtain the privacy types involved in the privacy behavior detection results, and find the corresponding privacy handling statements from the privacy policy;

[0064] S53. Compare the privacy behavior detection results with the actual processing method and privacy processing statement method of the same privacy type in the privacy policy to determine the privacy compliance of the third-party library of the mobile application, and record the privacy violation behavior of the third-party library of the mobile application.

[0065] In the embodiment of the present application, as Figure 5 shown, the privacy compliance determination module can be used to determine whether the detected risky privacy behavior of the third-party library complies with its privacy policy. The process can include: receiving the detection results from the privacy behavior detection module and obtaining the privacy policy corresponding to the third-party library. Analyze the detection results and the privacy policy to obtain the privacy types involved in the detection results, and find the corresponding privacy processing statements in the privacy policy. Compare the detection results with the actual processing method and statement method of the same privacy type in the privacy policy to determine the privacy compliance of the third-party library, and record the privacy violation behavior of the third-party library.

[0066] Through this embodiment, by performing static taint analysis on the third-party library encapsulated as an APK file to obtain its risky privacy behavior, and then performing consistency verification with the statements in its privacy policy, it is possible to discover privacy leakage problems existing in the third-party library of the mobile application and determine its privacy compliance.

[0067] According to another aspect of the embodiment of the present application, there is also provided a detection device for implementing the above-mentioned detection method of the third-party library of the mobile application based on static taint analysis. Figure 6 is a schematic structural diagram of an optional detection device for the third-party library of the mobile application based on static taint analysis according to the embodiment of the present application. As Figure 6 shown, the device may include:

[0068] A preprocessing unit 602, configured to preprocess the third-party library of the mobile application and encapsulate the third-party library of the mobile application into an APK file containing the third-party library;

[0069] An analysis unit 604, configured to convert the privacy behavior into a taint analysis detection rule in the form of a function signature, and perform static taint analysis on the encapsulated APK file containing the third-party library based on the privacy behavior detection rule to detect whether there are risky privacy behaviors in the APK file;

[0070] A verification unit 606, configured to extract the behaviors declared in the privacy policy of the third-party library of the mobile application, and perform consistency verification between the declared behaviors and the detected risky privacy behaviors of the third-party library of the mobile application;

[0071] A determination unit 608, configured to determine a privacy compliance determination result of the third-party library of the mobile application in case of a privacy behavior that is not declared or exceeds the declared scope in the privacy policy of the third-party library of the mobile application.

[0072] It should be noted that the preprocessing unit 602 in this embodiment can be used to execute the above step S102, the analysis unit 604 in this embodiment can be used to execute the above step S104, the verification unit 606 in this embodiment can be used to execute the above step S106, and the determination unit 608 in this embodiment can be used to execute the above step S108.

[0073] Through the above modules, by preprocessing the third-party library of the mobile application, the third-party library of the mobile application is encapsulated into an APK file containing the third-party library; the privacy behavior is converted into a taint analysis detection rule in the form of a function signature, and the static taint analysis tool is used to perform static taint analysis on the encapsulated APK file containing the third-party library based on the privacy behavior detection rule to detect whether there is a risky privacy behavior in the APK file; the behaviors declared in the privacy policy of the third-party library of the mobile application are extracted, and the declared behaviors are verified for consistency with the detected risky privacy behaviors of the third-party library of the mobile application; in case of a privacy behavior that is not declared or exceeds the declared scope in the privacy policy of the third-party library of the mobile application, the privacy compliance determination result of the third-party library of the mobile application is determined, which solves the problems of high complexity and insufficient accuracy in the relevant privacy compliance analysis and detection of the third-party library of the mobile application, and improves the accuracy and applicability of the privacy compliance detection of the third-party library of the mobile application.

[0074] In an exemplary embodiment, the preprocessing unit includes:

[0075] A creation module, configured to create an Android engineering project and complete the basic configurations required for the Android engineering project;

[0076] An import module, configured to import the source file of the third-party library of the mobile application into the Android engineering project;

[0077] A generation module, configured to automatically build the project and generate an APK file encapsulated by the third-party library of the mobile application.

[0078] In an exemplary embodiment, the analysis unit includes:

[0079] A building module for building a privacy behavior rule set for taint analysis, where the privacy behavior rule set includes taint sources and taint sinks. Among them, the taint sources include application information, device information, location information, multimedia information, network information, personal identity information, and contact and calendar information, and the taint sinks include network transmission, file storage, logging, database storage, Bluetooth / NFC transmission, and SMS / MMS transmission;

[0080] A labeling module for manually labeling the manifestation types of the taint sources and the taint sinks in the privacy behavior rule set, where the manifestation type is the way in which the taint sources and the taint sinks obtain or leak privacy in taint analysis.

[0081] In an exemplary embodiment, the device further includes:

[0082] A parsing unit for parsing the taint sources and the taint sinks using regular matching to obtain a parsing result;

[0083] A conversion unit for converting the parsing result into the taint analysis detection rule according to the requirements of the static taint analysis tool, where the taint analysis detection rule is in JSON format and determines the taint sources and the taint sinks in the form of a function signature.

[0084] In an exemplary embodiment, the analysis unit includes:

[0085] An acquisition unit for importing a standardized rule file from a detection rule specification module, building a privacy behavior model, parsing the encapsulated third-party library file from a data set preprocessing module, and obtaining basic information;

[0086] A configuration unit for completing the basic configuration of the static taint analysis tool according to the basic information and creating a new directory for storing privacy behavior detection results.

[0087] An output unit for detecting and outputting the privacy behavior existing in the mobile application third-party library based on the static taint analysis tool;

[0088] A statistical analysis unit for statistically analyzing the output result according to the categories of the taint sources and the taint sinks to generate a privacy behavior detection result.

[0089] In an exemplary embodiment, the device further includes:

[0090] A receiving unit for receiving the privacy behavior detection result from the privacy behavior detection module and obtaining the privacy policy corresponding to the mobile application third-party library;

[0091] A search unit for parsing the privacy behavior detection result and the privacy policy, obtaining the privacy types involved in the privacy behavior detection result, and searching for corresponding privacy handling statements from the privacy policy;

[0092] A determination unit for comparing the actual handling method of the same privacy type in the privacy behavior detection result and the privacy policy with the privacy handling statement method, determining the privacy compliance of the mobile application third-party library, and recording the privacy violation behavior of the mobile application third-party library.

[0093] It should be noted here that the implementation examples and scenarios of the above modules and corresponding steps are the same, but are not limited to the content disclosed in the above embodiments. It should be noted that the above modules, as part of the device, can run in a hardware environment, can be implemented by software, or can be implemented by hardware, where the hardware environment includes a network environment.

[0094] According to another aspect of the embodiments of the present application, a storage medium is further provided. Optionally, in this embodiment, the above storage medium can be used to execute the program code of any one of the above detection methods for mobile application third-party libraries based on static taint analysis in the embodiments of the present application.

[0095] Optionally, in this embodiment, the storage medium is set to store program code for executing the following steps:

[0096] S1, preprocess the mobile application third-party library, and encapsulate the mobile application third-party library into an APK file containing the third-party library;

[0097] S2, convert the privacy behavior into a taint analysis detection rule in the form of a function signature, and use a static taint analysis tool to perform static taint analysis on the encapsulated APK file containing the third-party library based on the privacy behavior detection rule to detect whether there are risky privacy behaviors in the APK file;

[0098] S3, extract the behaviors declared in the privacy policy of the mobile application third-party library, and verify the consistency between the declared behaviors and the detected risky privacy behaviors of the mobile application third-party library;

[0099] S4, in the case of privacy behaviors not declared in the privacy policy of the mobile application third-party library or exceeding the declared scope, determine the privacy compliance determination result of the mobile application third-party library.

[0100] Optionally, the specific examples in this embodiment can refer to the examples described in the above embodiments, and will not be elaborated here in this embodiment.

[0101] Among them, the computer-readable storage medium may include, but is not limited to, any type of disk, including floppy disks, optical disks, DVDs, CD-ROMs, microdrives, and magneto-optical disks, ROMs, RAMs, EPROMs, EEPROMs, DRAMs, VRAMs, flash memory devices, magnetic or optical cards, nanosystems (including molecular memory ICs), or any type of medium or device suitable for storing instructions and / or data.

[0102] According to another aspect of the embodiments of the present application, an electronic device for implementing the above-mentioned detection method of a third-party library of a mobile application based on static taint analysis is further provided. The electronic device may be a server, a terminal, or a combination thereof.

[0103] Figure 7 is a schematic structural diagram of an optional electronic device according to the embodiments of the present application, as Figure 7 shown, including a processor 702, a communication interface 704, a memory 706, and a communication bus 708. Among them, the processor 702, the communication interface 704, and the memory 706 complete mutual communication through the communication bus 708. Among them,

[0104] The memory 706 is used to store computer programs;

[0105] The processor 702, when executing the computer program stored on the memory 706, implements the following steps:

[0106] S1, preprocess the third-party library of the mobile application, and package the third-party library of the mobile application into an APK file containing the third-party library;

[0107] S2, convert the privacy behavior into a taint analysis detection rule in the form of a function signature, and use a static taint analysis tool to perform static taint analysis on the packaged APK file containing the third-party library based on the privacy behavior detection rule to detect whether there are risky privacy behaviors in the APK file;

[0108] S3, extract the behaviors declared in the privacy policy of the third-party library of the mobile application, and perform consistency verification on the declared behaviors and the detected risky privacy behaviors of the third-party library of the mobile application;

[0109] S4, in the case where there are privacy behaviors not declared or exceeding the declared scope in the privacy policy of the third-party library of the mobile application, determine the privacy compliance determination result of the third-party library of the mobile application.

[0110] Optionally, the communication bus may be a PCI (Peripheral Component Interconnect) bus, an EISA (Extended Industry Standard Architecture) bus, or the like. The communication bus may be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 7 only a thick line is used to represent it in Figure 7 , but it does not mean that there is only one bus or one type of bus. The communication interface is used for communication between the above-mentioned electronic device and other devices.

[0111] The memory may include a RAM, and may also include a non-volatile memory, for example, at least one disk memory. Optionally, the memory may also be at least one storage device located far from the aforementioned processor.

[0112] As an example, the above-mentioned memory 706 may but is not limited to include the preprocessing unit 602, the analysis unit 604, the verification unit 606, and the determination unit 608 in the above-mentioned detection device for third-party libraries of mobile applications based on static taint analysis. In addition, it may also include but is not limited to other module units in the above-mentioned detection device for third-party libraries of mobile applications based on static taint analysis, which will not be elaborated in this example.

[0113] The above-mentioned processor may be a general-purpose processor, which may include but is not limited to: a CPU (Central Processing Unit), an NP (Network Processor), etc.; it may also be a DSP (Digital Signal Processing), an ASIC (Application Specific Integrated Circuit), an FPGA (Field-Programmable Gate Array), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0114] Optionally, the specific examples in this embodiment may refer to the examples described in the above-mentioned embodiments, and will not be elaborated herein.

[0115] It should be noted that, for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence, because according to this application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to this application.

[0116] In the above embodiments, the descriptions of the respective embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0117] In the several embodiments provided by this application, it should be understood that the disclosed device can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some service interfaces. The indirect couplings or communication connections of the devices or units can be in electrical or other forms.

[0118] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0119] In addition, in each embodiment of this application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0120] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned memory includes: various media such as USB flash drives, read-only memories (ROM), random access memories (RAM), external hard drives, magnetic disks, or optical discs that can store program codes.

[0121] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing relevant hardware through a program. This program can be stored in a computer-readable memory, and the memory can include: flash drives, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical discs, etc.

[0122] The above are only exemplary embodiments of the present disclosure and should not be used to limit the scope of the present disclosure. That is, any equivalent changes and modifications made in accordance with the teachings of the present disclosure still fall within the scope covered by the present disclosure. Those skilled in the art will readily think of other embodiments of the present disclosure after considering the specification and practicing the present disclosure herein. This application aims to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common general knowledge or conventional technical means in the technical field not described in the present disclosure. The specification and embodiments are only regarded as exemplary, and the scope and spirit of the present disclosure are defined by the claims.

[0123] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as within the scope described in this specification.

[0124] Those skilled in the art can easily understand that the above are only preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principles of the present invention should be included in the protection scope of the present invention.

Claims

1. A method for detecting third-party libraries of mobile applications based on static taint analysis, characterized in that: include: Preprocessing the third-party library of the mobile application, and packaging the third-party library of the mobile application into an APK file including the third-party library; Convert the privacy behavior into a taint analysis detection rule in the form of a function signature, and use a static taint analysis tool to perform static taint analysis on the encapsulated APK file containing the third-party library based on the privacy behavior detection rule to detect whether the APK file has risky privacy behavior; Extract the behaviors declared in the privacy policy of the third-party library of the mobile application, and verify the consistency between the declared behaviors and the detected risky privacy behaviors of the third-party library of the mobile application; In the event that a privacy behavior occurs that is not declared in the privacy policy of the mobile application third-party library or exceeds the declared scope, a privacy compliance determination result of the mobile application third-party library is determined.

2. The method for detecting a third-party library of a mobile application based on static taint analysis according to claim 1, characterized in that: The preprocessing of the mobile application third-party library and packaging the mobile application third-party library into an APK file containing the third-party library includes: Create an Android project and complete the basic configuration required for the Android project; Import the source files of the third-party library of the mobile application into the Android project; Automatically build the project and generate an APK file encapsulated by the third-party library of the mobile application.

3. The method for detecting a third-party library of a mobile application based on static taint analysis according to claim 1, characterized in that: The taint analysis detection rule that converts the privacy behavior into a function signature form, uses the taint analysis tool to perform static taint analysis on the encapsulated APK file containing the third-party library based on the privacy behavior detection rule, and detects whether the APK file has risky privacy behavior, including: Constructing a privacy behavior rule set for taint analysis, the privacy behavior rule set includes taint sources and taint aggregation, wherein the taint sources include application information, device information, location information, multimedia information, network information, personal identity information, and contact and calendar information, and the taint aggregation includes network transmission, file storage, log record, database storage, Bluetooth / NFC transmission, SMS / MMS transmission; Manually label the performance type of the taint source and the taint aggregation in the privacy behavior rule set, wherein the performance type is the way in which the taint source and the taint aggregation obtain or leak privacy in the taint analysis.

4. The method for detecting a third-party library of a mobile application based on static taint analysis according to claim 3, characterized in that: After manually labeling the performance types of the taint sources and the taint aggregations in the privacy behavior rule set, the method further includes: Use regular matching to parse the taint source and the taint aggregation to obtain a parsing result; The analysis result is converted into the taint analysis detection rule according to the requirements of the static taint analysis tool, wherein the taint analysis detection rule adopts the JSON format and determines the taint source and the taint aggregation in the form of a function signature.

5. The method for detecting a third-party library of a mobile application based on static taint analysis according to claim 1, characterized in that: The static taint analysis tool is used to perform static taint analysis on the packaged APK file containing the third-party library based on the privacy behavior detection rule to detect whether the APK file has risky privacy behaviors, including: Import the standardized rule file from the detection rule specification module, build the privacy behavior model, parse the encapsulated third-party library file from the dataset preprocessing module, and obtain basic information; Complete the basic configuration of the static taint analysis tool based on the basic information, and create a new directory to store the privacy behavior detection results; Based on static taint analysis tools, detect privacy behaviors in third-party libraries of mobile applications and output results; The output result is statistically analyzed according to the categories of the taint sources and the taint aggregations to generate a privacy behavior detection result.

6. The method for detecting a third-party library of a mobile application based on static taint analysis according to claim 5, characterized in that: After performing statistical analysis on the output result according to the categories of the taint sources and the taint aggregations to generate a privacy behavior detection result, the method further includes: Receive the privacy behavior detection result from the privacy behavior detection module, and obtain the privacy policy corresponding to the third-party library of the mobile application; Parsing the privacy behavior detection result and the privacy policy, obtaining the privacy type involved in the privacy behavior detection result, and searching for the corresponding privacy processing statement from the privacy policy; The privacy behavior detection result is compared with the actual processing method and privacy processing declaration method of the same privacy type in the privacy policy, the privacy compliance of the third-party library of the mobile application is determined, and the privacy violation of the third-party library of the mobile application is recorded.

7. A detection device for a third-party library of a mobile application based on static taint analysis, characterized in that: include: A preprocessing unit, used to preprocess the third-party library of the mobile application and encapsulate the third-party library of the mobile application into an APK file containing the third-party library; An analysis unit, configured to convert the privacy behavior into a taint analysis detection rule in the form of a function signature, and use a static taint analysis tool to perform a static taint analysis on the encapsulated APK file containing the third-party library based on the privacy behavior detection rule to detect whether the APK file has risky privacy behavior; A verification unit, used to extract the behaviors declared in the privacy policy of the third-party library of the mobile application, and verify the consistency between the declared behaviors and the detected risky privacy behaviors of the third-party library of the mobile application; The determination unit is used to determine the privacy compliance determination result of the mobile application third-party library when a privacy behavior that is not declared in the privacy policy of the mobile application third-party library or exceeds the declared scope occurs.

8. The detection device for mobile application third-party library based on static stain analysis according to claim 7, characterized in that: The pre-processing unit comprises: A creation module is used to create an Android project and complete the basic configuration required for the Android project; An import module, used to import the source files of the third-party library of the mobile application into the Android project; The generation module is used to automatically build the project and generate an APK file encapsulated by the third-party library of the mobile application.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored program, wherein the program executes the method according to any one of claims 1 to 6 when executed.

10. An electronic device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to execute the method according to any one of claims 1 to 6 through the computer program.