Data monitoring method and device

By obtaining the memory address of the network request function of the client application and reading the data to be sent, the problem of incomplete monitoring of outbound data in the prior art is solved, and comprehensive monitoring of client and server data is realized, ensuring data compliance and security.

CN120223569APending Publication Date: 2025-06-27VIVO MOBILE COMM CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510355842.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

It is difficult for the prior art to conduct comprehensive outbound data monitoring, especially when client applications cannot be easily modified and adapted.

Method used

By obtaining the memory address of the network request function of the application running in the client, reading the data to be sent, and obtaining the data to be sent in the server, thereby monitoring the outbound data in the data to be sent in the client and the server.

Benefits of technology

It realizes comprehensive outbound data monitoring of data to be sent in the client and server, without modifying the client application, ensuring comprehensive monitoring and compliance of outbound data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223569A_ABST
    Figure CN120223569A_ABST
Patent Text Reader

Abstract

The invention discloses a data monitoring method and device, and belongs to the technical field of data processing. The method comprises the following steps: acquiring a memory address of a network request function of a first application running in a client; reading first data to be sent in the first application according to the memory address of the network request function; second data to be sent in a server side are obtained, and the first data and the second data comprise outbound data; and performing data monitoring on the outbound data in the first data and the second data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the technical field of data processing, and particularly relates to a method and device for monitoring data. Background Art

[0002] Nowadays, with the increasing requirements for data privacy and cross-border data transmission compliance, the monitoring of outbound data has gradually become stricter.

[0003] However, in the related art, to monitor data of an application, the application needs to be modified to meet the data monitoring requirements. However, the applications in the client cannot be easily modified and adapted. Therefore, it is currently difficult to obtain the network data in the client, resulting in the inability to monitor the outbound data in the client, and thus unable to comprehensively monitor the outbound data. Summary of the Invention

[0004] The purpose of the embodiments of this application is to provide a method and device for monitoring data, which can solve the technical problem that comprehensive monitoring of outbound data cannot be performed in the prior art.

[0005] In a first aspect, the embodiments of this application provide a method for monitoring data, the method comprising:

[0006] Obtaining the memory address of the network request function of a first application running in a client;

[0007] Reading first data to be sent in the first application according to the memory address of the network request function;

[0008] Obtaining second data to be sent in a server, wherein the first data and the second data include outbound data;

[0009] Performing data monitoring on the outbound data in the first data and the second data.

[0010] In a second aspect, the embodiments of this application provide a device for monitoring data, the device comprising:

[0011] A first obtaining module, configured to obtain the memory address of the network request function of a first application running in a client;

[0012] A reading module, configured to read first data to be sent in the first application according to the memory address of the network request function;

[0013] A second obtaining module, configured to obtain second data to be sent in a server, wherein the first data and the second data include outbound data;

[0014] A monitoring module, configured to perform data monitoring on the outbound data in the first data and the second data.

[0015] In a third aspect, an embodiment of the present application provides an electronic device, which includes a processor and a memory. The memory stores a program or instruction that can run on the processor. When the program or instruction is executed by the processor, the steps of the method provided in the first aspect are implemented.

[0016] In a fourth aspect, an embodiment of the present application provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method provided in the first aspect are implemented.

[0017] In a fifth aspect, an embodiment of the present application provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor, and the processor is used to run a program or instruction to implement the method provided in the first aspect.

[0018] In a sixth aspect, an embodiment of the present application provides a computer program product, which is stored in a storage medium and is executed by at least one processor to implement the method provided in the first aspect.

[0019] In the data monitoring method and device of the present application, the memory address of the network request function of the application program in the client can be obtained, and then the data to be sent can be read according to the memory address. The data to be sent in the server can also be obtained, and the outbound data in the data to be sent in the client and the server can be monitored. The present application does not need to modify the application program in the client, and can also monitor the data to be sent by obtaining the memory address of the network request function in the client. In this way, the present application can monitor both the data to be sent in the client and the data to be sent in the server, so as to achieve comprehensive monitoring of outbound data. Description of the Drawings

[0020] Figure 1 is a schematic flowchart of the data monitoring method provided by an embodiment of the present application;

[0021] Figure 2 is a schematic structural diagram of the data monitoring device provided by another embodiment of the present application;

[0022] Figure 3 is a schematic structural diagram of the electronic device provided by another embodiment of the present application;

[0023] Figure 4 is a schematic hardware structure diagram of the electronic device provided by the embodiment of the present application. Detailed Embodiments

[0024] Next, the technical solutions in the embodiments of the present application will be clearly described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art belong to the scope of protection of the present application.

[0025] The terms "first", "second", etc. in the description and claims of the present application are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second", etc. are usually of the same category, and do not limit the number of objects. For example, the first object can be one or multiple. In addition, "and / or" in the description and claims means at least one of the connected objects, and the character " / " generally indicates an "or" relationship between the associated objects before and after.

[0026] To solve the above technical problems, the present application provides a method for monitoring data. Next, in conjunction with the accompanying drawings, the method for monitoring data provided in the embodiments of the present application will be described in detail through specific embodiments and their application scenarios.

[0027] As Figure 1 shown, Figure 1 is a flowchart of a method for monitoring data provided in an embodiment of the present application. The embodiment of the present application provides a method for monitoring data, and the method may include:

[0028] S101, obtaining the memory address of the network request function of the first application running in the client;

[0029] In this embodiment, outbound data refers to data sent from one country or region to another country or region. Since outbound data involves cross-border transmission, it needs to be subject to relatively strict supervision. Data may go outbound through the client or through the server.

[0030] Specifically, outbound data through the client means that data is directly sent from the user's electronic device to an overseas server without being processed by the enterprise or organization's server. Among them, the user's electronic device may include the user's mobile phone or computer, etc. For example, when the user uses a social media application on the mobile phone to upload photos or post status, the data is directly sent from the mobile phone to the server of the social media application. If the server of the social media application is located overseas, then the photos uploaded by the user or the status posted are outbound data through the client.

[0031] Data transmitted out of the country through the server means that the data is first processed by the servers of an enterprise or organization, and then the processed data is uniformly sent from these servers to overseas servers. For example, if the internal system of an enterprise needs to send data to the server of a foreign cooperative company, the data will be sent from the enterprise's server to the cooperative company's server. At this time, the data sent is the data transmitted out of the country through the server.

[0032] The first application can be an application in the application whitelist and is a running application. The network request function refers to the function in the first application responsible for sending network requests. Through the network request function, communication can be carried out with a remote server. Therefore, when it is detected that there is a running first application in the client, the memory address of the network request function of the first application can be determined, and the first data to be sent in the first application can be read through this memory address, so as to realize the monitoring of the data in the client.

[0033] In some embodiments, obtaining the memory address of the network request function of the first application running in the client includes:

[0034] Obtain the system file in the first application;

[0035] Determine the base address of the network request library in the first application according to the system file;

[0036] Determine the offset address of the network request function relative to the base address;

[0037] Determine the memory address of the network request function according to the base address and the offset address.

[0038] In this embodiment, the network request library is a collection containing multiple functions and tools for initiating and managing network requests, and is used to process the network requests of the first application. Since the network request library includes network request functions. Therefore, the base address of the network request library can be determined first, where the base address of the network request library refers to the starting address of the network request library in memory. Through the base address, the first application can determine the loading position of the network request library in memory.

[0039] After determining the base address of the network request library, the offset address of the network request function relative to the network request library can be further determined. Finally, by combining the base address and the offset address, the actual memory address of the network request function can be obtained.

[0040] Specifically, the system files in the first application can be read first. The system files contain the memory mapping information of the specified process in the first application. Through the memory mapping information, the base address where the network request library starts can be located. Among them, the system files can include virtual files such as proc files, pid files, and maps files. Then, the offset address of the network request function in the network request library relative to the base address can be further determined. Finally, the actual memory address of the network request function can be obtained by combining the offset address and the base address.

[0041] Exemplarily, by parsing the symbol table in the ELF file, the key network features in the ELF file can be obtained, and the offset address of the network request function can be obtained through the key network features. Among them, the key network features in the symbol table record the offset addresses of each function in the network request library.

[0042] In the above-mentioned manner, by obtaining the base address of the network request library of the client application and the offset address of the network request function, the actual memory address of the network request function can be accurately located, so as to realize the monitoring of the data in the client.

[0043] S102, read the first data to be sent in the first application according to the memory address of the network request function;

[0044] In this embodiment, after obtaining the memory address of the network request function of the first application, the input parameters of the network request function can be parsed through the memory address of the network request function, and then the data corresponding to the network request function stored in the register can be found. These data are the first data to be sent through the network request function. The first data can include a URL (Uniform Resource Locator), a request body, and a request header. Among them, the URL is the address to which the first data request is sent, the request body is the main body of the data to be sent, and the request header includes the content type and authentication information, etc. in the data to be sent.

[0045] Since these data will be stored in the register before data transmission, the first data to be sent in the first application can be obtained by reading the information stored in the register.

[0046] S103, obtain the second data to be sent in the server, where the first data and the second data include outbound data.

[0047] In the embodiment of the present application, after obtaining the first data to be sent in the client, the second data to be sent in the server can also be obtained. Exemplarily, a data sending port can be set in the server, and the second data to be sent in the server can be obtained from the data sending port.

[0048] S104, perform data monitoring on the outbound data in the first data and the second data.

[0049] In the embodiments of the present application, after obtaining the second data to be sent in the server and the first data to be sent in the client, the outbound data in the first data and the second data can be filtered out, and then only the outbound data in the first data and the second data is monitored.

[0050] During the data monitoring process, it can be monitored whether the outbound data contains personal information or other sensitive data. If the frequency or quantity of personal information or other sensitive data transmission is too high, an alarm can be issued to prevent a large amount of sensitive data from being leaked.

[0051] In the embodiments of the present application, the memory address of the network request function of the application program in the client can be obtained, and then the data to be sent is read according to the memory address, and the data to be sent in the server is obtained, and the outbound data in the data to be sent in the client and the server is monitored. The present application does not need to modify the application program in the client, and can also monitor the data to be sent by obtaining the memory address of the network request function in the client. In this way, the present application can monitor both the data to be sent in the client and the data to be sent in the server, so as to achieve comprehensive monitoring of outbound data.

[0052] Specifically, in some embodiments, the performing data monitoring on the outbound data in the first data and the second data includes:

[0053] Obtain the personal information in the outbound data in the first data and the second data;

[0054] When the quantity of the personal information is greater than the first threshold, output an alarm prompt message.

[0055] In this embodiment, the personal information is identity information related to natural persons, and may include the name, mobile phone number, address, gender, age, ID number, consumption record, etc. of natural persons. Since personal information involves personal privacy, the personal information in the outbound data needs to be supervised.

[0056] The personal information in the outbound data in the first data and the second data can be identified in each supervision period, and then the personal information is summarized. If the quantity of the personal information is greater than the preset first threshold, it can be considered that the quantity of the outbound personal information is too large and an alarm is required. Therefore, an alarm prompt message can be output to relevant monitoring departments or monitoring personnel; if the quantity of the personal information is less than or equal to the first threshold, it is considered that the outbound personal information is in the normal range and no alarm is required.

[0057] For example, in a certain regulatory period, the number of natural persons' names in the outbound data is 2,000, the number of mobile phone numbers is 2,000, the number of addresses is 5,000, and the number of ID card numbers is 1,000. Then the number of personal information is 10,000. If the first threshold is 9,000, then the number of personal information is greater than the first threshold, and an alarm prompt message needs to be output.

[0058] In this embodiment, through the above method, the number of personal information in the outbound data can be monitored, and an alarm is triggered when the number of personal information exceeds the set threshold, so as to identify potential data leakage risks in a timely manner and avoid a large amount of sensitive data leakage.

[0059] In some embodiments, obtaining the personal information in the outbound data in the first data and the second data includes:

[0060] Obtaining an outbound identification field associated with the third data, where the third data is the second data including the associated outbound identification field, and the outbound identification field is used to indicate that the second data associated with it is outbound data;

[0061] Obtaining the personal information in the third data from the outbound identification field.

[0062] In this embodiment, since the second data is the data sent through the server, for some second data, the data business requester can provide a data outbound report, which records and reports the data outbound behavior. Therefore, an outbound identification field can be added to the second data based on the data outbound report. The outbound identification field is used to indicate that there is outbound data in the corresponding data, and the detailed information related to personal information in the corresponding data is recorded in the outbound identification field.

[0063] Specifically, the corresponding relationship between a specific request and outbound information can be defined in the data outbound report. For example, the data outbound report can record that request A contains 10 pieces of personal information sent overseas, and the data outbound report can also record that request B does not include information sent overseas. Then, an outbound identification field can be added to request A, and the outbound identification field can include the id of request A and the personal information in the outbound data in the structured request A, and no outbound identification field is added to request B.

[0064] Then, after the second data is generated, it can be detected whether there is an associated outbound identification field in the second data. If there is an associated outbound identification field, the second data is determined as the third data, and the personal information in the third data can be directly read from the outbound identification field.

[0065] Through the above method, it is possible to accurately track the outbound data in the second data based on whether there is an associated outbound identification field in the data, and directly extract the personal information in the outbound data from the outbound identification field, improving the monitoring efficiency of the outbound data.

[0066] In some embodiments, obtaining the personal information in the outbound data of the first data and the second data includes:

[0067] Obtaining the target network address of the fourth data, where the fourth data includes the first data and the second data that does not include an associated outbound identification field;

[0068] When the target network address of the fourth data is an overseas network address, determining the fourth data as the outbound data and identifying the personal information in the fourth data.

[0069] In this embodiment, for the first data and the second data without an associated outbound identification field, it is impossible to determine whether they are outbound data through their relevant identifiers. Therefore, they can be used as the fourth data. And obtain the network (IP) address of the target server of the fourth data as the target network address of the fourth data.

[0070] If the target network address of the fourth data is an overseas network address, then it can be determined that the fourth data is the outbound data and needs to be monitored, and then the personal information in the fourth data can be identified; if the target network address of the fourth data is not an overseas network address, then the fourth data is not the outbound data, that is, there is no need to monitor it.

[0071] Exemplarily, the fourth data can be input into a trained large language model, and the large language model can directly read the semantics of the fourth data to identify the personal information in the fourth data.

[0072] In the above method, it is possible to accurately identify the outbound data by checking whether the target network address of the data is an overseas address, and further extract the personal information therein to ensure the compliance and security of cross-border data transmission.

[0073] In some embodiments, after identifying the personal information in the fourth data, the method further includes:

[0074] Structuring the personal information in the fourth data to obtain structured information;

[0075] Deleting the information of the target category from the structured information to obtain the first information;

[0076] Determining the number of personal information in the first information as the number of personal information in the fourth data.

[0077] In this embodiment, since it is necessary to count the quantity of personal information in the outbound data, the quantity of personal information in the third data and the quantity of personal information in the fourth data can be counted separately, and the sum of the quantity of personal information in the third data and the quantity of personal information in the fourth data is used as the quantity of personal information in the final outbound data.

[0078] The quantity of personal information in the third data can be directly obtained from the outbound identification field associated with the third data. For the fourth data, after identifying the personal information in the fourth data, the filtered personal information can be first regularized to identify and extract personal information that conforms to a specific format, such as telephone numbers, ID numbers, email addresses, etc.

[0079] After regularizing the personal information in the fourth data, the personal information with a determined format can be structured. The structuring process can convert the personal information into a key-value pair format. For example, if the personal information is originally "The telephone number of user A is 133xxxxxxxx", the structuring process can obtain structured information in key-value pair format: {data = 133xxxxxxxx; data Class = telephone number; name = Ding xx}.

[0080] In addition, the target category of personal information can be set in advance. The personal information of the target category is the security information that is set in advance and does not need to be monitored. Therefore, the information of the target category in the structured information needs to be filtered out to obtain the first information. Then, multiple duplicate personal information generated by the same user in the first information can be removed, and the quantity of personal information in the first information after deduplication can be counted, and the quantity of personal information in the first information is determined as the quantity of personal information in the fourth data.

[0081] In this embodiment, through the structuring and screening of personal information, the personal information that meets the requirements can be accurately extracted to ensure the accurate counting of the quantity of personal information.

[0082] Figure 2 It is a schematic structural diagram of a data monitoring device provided by another embodiment of the present application, as Figure 2 shown. The data monitoring device may include:

[0083] A first acquisition module 201, configured to acquire the memory address of the network request function of the first application running in the client;

[0084] A reading module 202, configured to read the first data to be sent in the first application according to the memory address of the network request function;

[0085] The second acquisition module 203 is configured to acquire second data to be sent in the server, where the first data and the second data include outbound data;

[0086] The monitoring module 204 is configured to perform data monitoring on the outbound data in the first data and the second data.

[0087] In this application, the memory address of the network request function of the application program in the client can be obtained, and then the data to be sent can be read according to the memory address, and the data to be sent in the server can be obtained, and the outbound data in the data to be sent in the client and the server can be monitored. This application does not need to modify the application program in the client, and can also monitor the data to be sent by obtaining the memory address of the network request function in the client. In this way, this application can monitor both the data to be sent in the client and the data to be sent in the server, so as to achieve comprehensive monitoring of outbound data.

[0088] In another optional example, the monitoring module 204 includes:

[0089] The first acquisition unit is configured to acquire personal information in the outbound data in the first data and the second data;

[0090] The output unit is configured to output an alarm prompt message when the quantity of the personal information is greater than a first threshold.

[0091] In another optional example, the first acquisition unit includes:

[0092] The first acquisition subunit is configured to acquire an outbound identification field associated with third data, where the third data is the second data including the associated outbound identification field, and the outbound identification field is used to indicate that the second data associated with it is outbound data;

[0093] The second acquisition subunit is configured to acquire personal information in the third data from the outbound identification field.

[0094] In another optional example, the first acquisition unit further includes:

[0095] The third acquisition subunit is configured to acquire the target network address of fourth data, where the fourth data includes the first data and the second data that does not include the associated outbound identification field;

[0096] The determination subunit is configured to determine the fourth data as the outbound data and identify the personal information in the fourth data when the target network address of the fourth data is an overseas network address.

[0097] In another optional example, the first acquisition module 201 includes:

[0098] A second acquisition unit, configured to acquire system files in the first application;

[0099] A first determination unit, configured to determine the base address of the network request library in the first application according to the system files;

[0100] A second determination unit, configured to determine the offset address of the network request function relative to the base address;

[0101] A third determination unit, configured to determine the memory address of the network request function according to the base address and the offset address.

[0102] The data monitoring device in the embodiments of the present application may be an electronic device or a component in an electronic device, such as an integrated circuit or a chip. The electronic device may be a terminal or other devices other than a terminal. Exemplarily, the electronic device may be a mobile phone, a tablet computer, a laptop computer, a handheld computer, a vehicle-mounted electronic device, a Mobile Internet Device (MID), an augmented reality (AR) / virtual reality (VR) device, a robot, a wearable device, an ultra-mobile personal computer (UMPC), a netbook, or a personal digital assistant (PDA), etc. It may also be a server, a Network Attached Storage (NAS), a personal computer (PC), a television (TV), a teller machine, or a self-service machine, etc. The embodiments of the present application do not make specific limitations.

[0103] The data monitoring device in the embodiments of the present application may be a device with an operating system. The operating system may be an Android operating system, an IOS operating system, or other possible operating systems. The embodiments of the present application do not make specific limitations.

[0104] The data monitoring device provided in the embodiments of the present application can implement Figure 1The various processes implemented by the method embodiments will not be elaborated here to avoid repetition.

[0105] Optionally, as Figure 3 shown, an embodiment of the present application further provides an electronic device 100, including a processor 110, a memory 119, a program or instruction stored on the memory 119 and executable on the processor 110. When the program or instruction is executed by the processor 110, it implements the various processes of the data monitoring method embodiment described above and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.

[0106] It should be noted that the electronic devices in the embodiments of the present application include the above-mentioned mobile electronic devices and non-mobile electronic devices.

[0107] Please refer to Figure 4 , Figure 4 which is a schematic diagram of the hardware structure of an electronic device for implementing an embodiment of the present application. The electronic device 100 includes but is not limited to: a radio frequency unit 121, a network module 122, an audio output unit 123, an input unit 124, a sensor 125, a display unit 126, a user input unit 127, an interface unit 128, a memory 129, and a processor 120, etc.

[0108] Those skilled in the art can understand that the electronic device 100 may further include a power supply (such as a battery) for supplying power to each component. The power supply can be logically connected to the processor 120 through a power management system, so as to implement functions such as management of charging, discharging, and power consumption management through the power management system. Figure 4 The structure of the electronic device shown in

[0109] does not limit the electronic device. The electronic device may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be elaborated here.

[0110]

[0111]

[0112]

[0113] wherein, the processor 120 is configured to obtain the memory address of the network request function of the first application running in the client;

[0113] In this application, the memory address of the network request function of the application in the client can be obtained, and then the data to be sent can be read according to the memory address, and the data to be sent in the server can be obtained, and the outbound data in the data to be sent in the client and the server can be monitored. This application does not need to modify the application in the client, and can also monitor the data to be sent by obtaining the memory address of the network request function in the client. In this way, this application can monitor both the data to be sent in the client and the data to be sent in the server, so as to achieve comprehensive monitoring of outbound data.

[0114] In another optional example, the processor 120 is further configured to:

[0115] Obtain the personal information in the outbound data in the first data and the second data;

[0116] Output an alarm prompt message when the number of the personal information is greater than a first threshold.

[0117] In another optional example, the processor 120 is further configured to:

[0118] Obtain an outbound identification field associated with the third data, where the third data is the second data including the associated outbound identification field, and the outbound identification field is used to indicate that the second data associated with it is outbound data;

[0119] Obtain the personal information in the third data from the outbound identification field.

[0120] In another optional example, the processor 120 is further configured to:

[0121] Obtain the target network address of the fourth data, where the fourth data includes the first data and the second data that does not include the associated outbound identification field;

[0122] When the target network address of the fourth data is an overseas network address, determine the fourth data as the outbound data and identify the personal information in the fourth data.

[0123] In another optional example, the processor 120 is further configured to:

[0124] Obtain the system file in the first application;

[0125] Determine the base address of the network request library in the first application according to the system file;

[0126] Determine the offset address of the network request function relative to the base address;

[0127] Determine the memory address of the network request function according to the base address and the offset address.

[0128] It should be understood that in the embodiments of the present application, the input unit 124 may include a Graphics Processing Unit (GPU) 1241 and a microphone 1242. The graphics processor 1241 processes the image data of static pictures or videos obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode. The display unit 126 may include a display panel 1261, and the display panel 1261 may be configured in the form of a liquid crystal display, an organic light emitting diode, etc. The user input unit 127 includes at least one of a touch panel 1271 and other input devices 1272. The touch panel 1271 is also referred to as a touch screen. The touch panel 1271 may include two parts: a touch monitoring device and a touch controller. The other input devices 1272 may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, power on / off keys, etc.), a trackball, a mouse, and a joystick, which will not be elaborated here.

[0129] The memory 129 can be used to store software programs and various data. The memory 129 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data. Among them, the first storage area may store an operating system, application programs or instructions required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory 129 may include a volatile memory or a non-volatile memory, or the memory 129 may include both a volatile memory and a non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDR SDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synch link dynamic random access memory (SLDRAM), and a direct rambus random access memory (DRRAM). The memory 129 in the embodiments of the present application includes, but is not limited to, these and any other suitable types of memories.

[0130] The processor 120 may include one or more processing units; optionally, the processor 120 integrates an application processor and a modem processor. Among them, the application processor mainly processes operations related to the operating system, user interface, and application programs, etc., and the modem processor mainly processes wireless communication signals, such as a baseband processor. It can be understood that the above modem processor may not be integrated into the processor 120 either.

[0131] The embodiments of the present application also provide a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, it implements each process of the above embodiment of the data monitoring method and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.

[0132] Among them, the processor is the processor in the electronic device in the above-mentioned embodiment. The readable storage medium includes computer-readable storage media, such as computer read-only memory ROM, random access memory RAM, magnetic disk or optical disc, etc.

[0133] Another embodiment of the present application provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement each process of the above-mentioned embodiment of the data monitoring method, and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.

[0134] It should be understood that the chip mentioned in the embodiment of the present application may also be referred to as a system-on-chip, system chip, chip system, or system-on-chip, etc.

[0135] The embodiment of the present application provides a computer program product, which is stored in a storage medium. The program product is executed by at least one processor to implement each process of the above-mentioned embodiment of the data monitoring method, and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.

[0136] It should be noted that in this article, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of another identical element in the process, method, article or device including the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in a reverse order according to the functions involved. For example, the described methods may be performed in an order different from that described, and various steps may be added, omitted, or combined. In addition, the features described with reference to certain examples may be combined in other examples.

[0137] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, can be embodied in the form of a computer software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disc), and includes several instructions for causing a terminal (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in various embodiments of the present application.

[0138] The embodiments of the present application have been described above in conjunction with the accompanying drawings. However, the present application is not limited to the above specific embodiments. The above specific embodiments are merely illustrative rather than restrictive. Under the inspiration of the present application, those of ordinary skill in the art can also make many forms without departing from the purpose of the present application and the scope protected by the claims, and all of them fall within the protection scope of the present application.

Claims

1. A data monitoring method, characterized in that: include: Obtaining a memory address of a network request function of a first application running in the client; Reading first data to be sent in the first application according to the memory address of the network request function; Acquire second data to be sent from the server, wherein the first data and the second data include outbound data; Data monitoring is performed on the outbound data in the first data and the second data.

2. The method according to claim 1, characterized in that The performing data monitoring on the outbound data in the first data and the second data includes: Acquire personal information in the outbound data in the first data and the second data; When the amount of the personal information is greater than a first threshold, an alarm prompt message is output.

3. The method according to claim 2, characterized in that The obtaining of personal information in the outbound data in the first data and the second data includes: Acquire an outbound identification field associated with third data, wherein the third data is second data including an associated outbound identification field, and the outbound identification field is used to indicate that the second data associated therewith is outbound data; The personal information in the third data is obtained from the exit identification field.

4. The method according to claim 2, characterized in that: The obtaining of personal information in the outbound data in the first data and the second data includes: Acquire a target network address of fourth data, wherein the fourth data includes the first data and the second data excluding an associated outbound identification field; In a case where the target network address of the fourth data is an overseas network address, the fourth data is determined as the outbound data, and personal information in the fourth data is identified.

5. The method according to claim 1, characterized in that The obtaining the memory address of the network request function of the first application running in the client includes: Obtaining a system file in the first application; Determine the base address of the network request library in the first application according to the system file; Determining an offset address of the network request function relative to the base address; The memory address of the network request function is determined according to the base address and the offset address.

6. A data monitoring device, characterized in that: include: A first acquisition module, used to acquire a memory address of a network request function of a first application running in a client; A reading module, used for reading first data to be sent in the first application according to the memory address of the network request function; A second acquisition module, used for acquiring second data to be sent from the server, wherein the first data and the second data include outbound data; A monitoring module is used to monitor the outbound data in the first data and the second data.

7. The device according to claim 6, characterized in that The monitoring module comprises: A first acquisition unit, configured to acquire personal information in the outbound data in the first data and the second data; The output unit is used to output warning information when the amount of the personal information is greater than a first threshold.

8. The device according to claim 7, characterized in that The first acquiring unit includes: a first acquisition subunit, configured to acquire an outbound identification field associated with third data, wherein the third data is second data including an associated outbound identification field, and the outbound identification field is used to indicate that the second data associated therewith is outbound data; The second acquisition subunit is used to acquire the personal information in the third data from the exit identification field.

9. The device according to claim 7, characterized in that The first acquisition unit further includes: a third acquisition subunit, configured to acquire a target network address of fourth data, wherein the fourth data includes the first data and the second data excluding an associated outbound identification field; A determination subunit is used to determine the fourth data as the outbound data when the target network address of the fourth data is an overseas network address, and to identify personal information in the fourth data.

10. The device according to claim 6, characterized in that The first acquisition module includes: A second acquisition unit, configured to acquire a system file in the first application; A first determining unit, configured to determine a base address of a network request library in the first application according to the system file; A second determining unit, configured to determine an offset address of the network request function relative to the base address; The third determining unit is used to determine the memory address of the network request function according to the base address and the offset address.