Application program anomaly detection method and device

By injecting agents into the application, obtaining request parameters and user IDs, determining whether they are used as operation parameters for database operations, and querying the data table mapping relationship for permission verification, the problem of access permission abnormalities in complex applications is solved, and the accuracy and security of detection are improved.

CN120296728APending Publication Date: 2025-07-11ANT GALAXY (CHONGQING) INFORMATION TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510408371.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-28
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

How to provide effective access control mechanisms in complex applications to ensure data security, especially when processing large amounts of data, to prevent permission exceptions and data leakage.

Method used

By injecting a proxy into the application, obtaining the request parameters and user ID of the access request, determining whether it is used as an operation parameter of the database operation, and querying whether the data table corresponding to the database operation has a data mapping relationship with the user ID, and performing permission verification based on the query results.

Benefits of technology

Improve the accuracy of abnormal detection of application access requests, reduce the missed and false alarm rates, and ensure the legitimacy of access permissions and data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296728A_ABST
    Figure CN120296728A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an application program anomaly detection method and device.The application program anomaly detection method comprises the steps that in the process of conducting anomaly detection on an application program, request parameters and a user identifier for conducting access request processing on the application program are obtained, then judging whether the request parameter and the user identifier serve as operation input parameters for executing database operation corresponding to the access request or not, and when at least one of the request parameter and the user identifier is not the operation input parameters of the database operation, querying whether a data mapping relationship exists between a data table corresponding to the database operation and the user identifier or not; and according to a detection strategy corresponding to the query result, performing permission verification detection on the database operation so as to realize detection processing on the access permission abnormity of the access request of the application program.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This document relates to the field of data security technology, and particularly to an abnormal detection method and device for an application program. Background Art

[0002] With the continuous development of information technology, the user roles and permission settings involved in application programs are becoming increasingly complex. In this case, while processing a large amount of data, application programs also need to manage relevant access permissions to ensure the data security of application programs while maintaining their stable operation. Therefore, how to further provide an effective access control mechanism to ensure the data security of application programs has become the focus of attention in the industry. Summary of the Invention

[0003] One or more embodiments of this specification provide an abnormal detection method for an application program, including: obtaining request parameters and user identifiers for the application program to process access requests; the request parameters and the user identifiers are collected through a proxy program injected by the application program. Judging whether the request parameters and the user identifiers are used as operation input parameters for the database operation corresponding to the execution of the access request. If not, querying whether there is a data mapping relationship between the data table corresponding to the database operation and the user identifier, and performing a detection of permission verification on the database operation according to the detection strategy corresponding to the query result.

[0004] One or more embodiments of this specification provide an abnormal detection device for an application program, including: a data acquisition module configured to obtain request parameters and user identifiers for the application program to process access requests; the request parameters and the user identifiers are collected through a proxy program injected by the application program. An operation input parameter detection module configured to judge whether the request parameters and the user identifiers are used as operation input parameters for the database operation corresponding to the execution of the access request, and if not, run a permission verification detection module. A permission verification detection module configured to query whether there is a data mapping relationship between the data table corresponding to the database operation and the user identifier, and perform a detection of permission verification on the database operation according to the detection strategy corresponding to the query result.

[0005] One or more embodiments of this specification provide an abnormal detection device for an application program, including: a processor; and a memory configured to store computer-executable instructions, which when executed cause the processor to: obtain request parameters and a user identifier for processing an access request by the application program; the request parameters and the user identifier are obtained by collecting through a proxy program injected by the application program. Determine whether the request parameters and the user identifier are used as operation input parameters for executing a database operation corresponding to the access request. If not, query whether there is a data mapping relationship between the data table corresponding to the database operation and the user identifier, and perform a detection of permission verification on the database operation according to the detection policy corresponding to the query result.

[0006] One or more embodiments of this specification provide a computer-readable storage medium for storing computer-executable instructions, which when executed implement the following process: obtain request parameters and a user identifier for processing an access request by the application program; the request parameters and the user identifier are obtained by collecting through a proxy program injected by the application program. Determine whether the request parameters and the user identifier are used as operation input parameters for executing a database operation corresponding to the access request. If not, query whether there is a data mapping relationship between the data table corresponding to the database operation and the user identifier, and perform a detection of permission verification on the database operation according to the detection policy corresponding to the query result. Description of the Drawings

[0007] In order to more clearly illustrate the technical solutions in one or more embodiments of this specification or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in this specification. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings; Figure 1 It is a schematic diagram of an implementation environment of an abnormal detection method for an application program provided by one or more embodiments of this specification; Figure 2 It is a processing flow chart of an abnormal detection method for an application program provided by one or more embodiments of this specification; Figure 3 It is a processing flow chart of an abnormal detection method for an application program applied to a Web application scenario provided by one or more embodiments of this specification; Figure 4 It is a processing flow chart of an abnormal detection method for an application program applied to a program abnormal detection scenario provided by one or more embodiments of this specification; Figure 5Schematic diagram of an embodiment of an abnormal detection device for an application provided for one or more embodiments of this specification; Figure 6 Schematic structural diagram of an abnormal detection device for an application provided for one or more embodiments of this specification. Detailed implementation manners

[0008] In order to enable those skilled in the art to better understand the technical solutions in one or more embodiments of this specification, the following will clearly and completely describe the technical solutions in one or more embodiments of this specification with reference to the accompanying drawings in one or more embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all the embodiments. Based on one or more embodiments of this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this document.

[0009] The abnormal detection method for an application provided for one or more embodiments of this specification is applicable to the implementation environment of abnormal detection of an application. Refer to Figure 1 , this implementation environment at least includes: a server 101; in addition, this implementation environment may further include a client 102; Among them, the server 101 is used to obtain the access request for the application 102-1 submitted by the client 102, and perform detection and processing on whether there is an abnormal access permission for the obtained access request. The server 101 can run on a server, and the server can be a single server or multiple servers, or a server cluster composed of several servers, or one or more cloud servers in a cloud computing platform; The client 102 runs the application 102-1, and the proxy program 102-2 is injected into the application 102-1; the client 102 is used to obtain the access request for the application 102-1 by the user and submit it to the server 101, so that the server obtains the access request and performs detection and processing on whether there is an abnormal access permission for the access request. The client 102 can run on a terminal device, and the terminal device can specifically be a mobile phone, a personal computer, a tablet computer, an e-book reader, a device for information interaction based on VR (Virtual Reality), a vehicle-mounted terminal, an IoT device, a wearable intelligent device, a laptop computer, a desktop computer, and so on; In this implementation environment, during the process of detecting anomalies in an application, based on the access request submitted by the client 102 for the application 102-1 obtained by the server 101, the server 101 obtains the request parameters and user identification for processing the access request of the application, and then determines whether the request parameters and the user identification are the operation input parameters for executing the database operation corresponding to the access request. In the case where at least one of the request parameters and the user identification is not the operation input parameter of the database operation, it queries whether there is a data mapping relationship between the data table corresponding to the database operation and the user identification, and performs a detection of permission verification on the database operation based on the detection policy corresponding to the query result, so as to implement the detection and processing of whether there is an anomaly in the access permission of the access request of the application.

[0010] It should be noted that considering that relevant data such as the user identification of the users involved in this specification may, to a certain extent, belong to the privacy of the users. Therefore, if you want to obtain relevant data such as user identification, you can obtain the authorization of the user before obtaining the data to make the operation of obtaining the data comply with relevant data management regulations. For example, the user can perform data authorization when starting the application. The specific method of data authorization can be to send a data authorization reminder to the user, and the user can obtain data authorization after confirming the reminder through an instruction. Or, the method of data authorization can also be to obtain data collection or data transmission authorization by signing a data authorization agreement. This embodiment does not make a limitation here.

[0011] One or more embodiments of an application anomaly detection method provided in this specification are as follows: Refer to Figure 2 In this embodiment, the application anomaly detection method provided includes steps S202 to S206 specifically.

[0012] Step S202: Obtain the request parameters and user identification for processing the access request of the application.

[0013] The application in this embodiment can be a program running on the client. For example, the application can be a Web application, or a mobile application installed on a mobile device, or a desktop application installed and running on a user's computer. In this case, the application can also be replaced by a front-end program. In addition, the application can also be a program running on the server, or the application can also be the server system program itself. In this case, the application can be replaced by a server program, or the application can also be replaced by a back-end program. Or, the application can also be an application whose access permission is detected during the process of processing the access request. In this case, the application can also be replaced by a program to be detected.

[0014] In this embodiment, by injecting a proxy program into the application, the running data of the application is obtained, and by extracting the access requests of the application, the request parameters included in the access requests, and / or other data related to the running of the application from the running data and uploading them, the server is thereby assisted in detecting whether there are any abnormal access permissions for the access requests of the application based on the running data collected by the proxy program. Optionally, the request parameters and user identifiers are obtained by collecting through the proxy program injected into the application.

[0015] Among them, the proxy program refers to a program deployed in the application and providing the running data of the application to the server. For example, the specific form of the proxy program can be an SDK (Software Development Kit, application development toolkit) deployed on the application; the request parameters refer to the parameters carried by the request, specifically, the parameters carried by the access request of the application; the running data can be the stack data during the running of the application; the abnormal access permission means that the permission for the current user's access request to the application is not verified, enabling the current user to access other users' related data by modifying relevant parameters. For example, the current user can access or operate the data of another user with the same permission level (i.e., horizontal privilege escalation vulnerability).

[0016] During specific implementation, in the process of obtaining the request parameters and user identifiers for the application to process the access request, specifically, when the application is a front-end program and a proxy program is injected into the application, the proxy program obtains the stack data of the application running, and obtains the access request of the user for the application, the request parameters carried by the access request, and the user identifier from the stack data and uploads them. Correspondingly, the request parameters and user identifiers for the application to process the access request uploaded by the proxy program are received. In addition, when the application is a back-end program and a proxy program is injected into the application, after the proxy program obtains the stack data of the application running and obtains the access request of the user for the application, the request parameters carried by the access request, and the user identifier from the stack data, the request parameters and user identifiers for the application to process the access request collected by the proxy program are obtained.

[0017] During the specific execution process, in an optional implementation manner provided by this embodiment, the proxy program obtains and uploads the request parameters and user identifiers in the following manner: obtaining the stack data of the application, and reading and uploading the request parameters and user identifiers from the stack data.

[0018] Specifically, the proxy program can read the request parameters and user identification from the stack data and upload them; alternatively, the proxy program can also read the request parameters and the user's session identification from the stack data, and then obtain the user identification corresponding to the conversation identification, so as to obtain the request parameters and user identification of the access request and upload them.

[0019] In practical applications, after obtaining the request parameters carried by the access request, it is possible to determine whether the request parameters are used to construct or affect database operations by determining whether the request parameters directly or indirectly participate in database operations, so as to determine whether there is a risk of abnormal access permissions for the access request. In an optional implementation provided in this embodiment, after obtaining the request parameters and user identification for processing the access request by the application program, it further includes: Detect whether the request parameter is an input parameter for a database operation; If not, it is determined that there is no abnormal access permission for the access request; If so, perform the following step S204 to determine whether the request parameter and user identification are input parameters for executing the database operation corresponding to the access request.

[0020] Specifically, after obtaining the request parameter and user identification, it is possible to first detect whether the request parameter is an input parameter for part of a database operation. If the request parameter is not an input parameter for a database operation, it means that the current access request will not directly or indirectly affect the data in the database. For example, if the current access request is only to obtain static resources and / or execute operations that do not involve the database, it indicates that there is no abnormal access permission for the access request; if the request parameter is an input parameter for a database operation, it indicates that the request parameter of the current access request participates in the database operation, and there may be a situation of accessing or modifying the data stored in the database. Therefore, it is necessary to determine whether the request parameter and user identification are input parameters for executing the database operation corresponding to the access request through step S204.

[0021] For example, during the process of detecting the access permission of the access request of the application program, it is possible to detect whether the request parameter is a parameter of an SQL (Structured Query Language) query statement. If the request parameter is not used as an SQL query, it does not involve data operations, and it can be considered that the possibility of abnormal access permission for the access request is small, and subsequent detection operations may not be performed. On the contrary, if the request parameter is an SQL query parameter, it is necessary to further determine whether the request parameter and user identification are input parameters for executing the database operation corresponding to the access request.

[0022] In addition, in practical applications, during the process of detecting access permissions for access requests to an application, in order to improve the overall detection efficiency, it is also possible to first detect whether the access request contains request parameters to filter out requests that do not involve database operations. In an optional implementation provided in this embodiment, before obtaining the request parameters and user identification for processing the access request by the application, it further includes: Detect whether the access request contains request parameters; If it contains request parameters, execute step S202 to obtain the request parameters and user identification for processing the access request by the application; If it does not contain request parameters, determine that there is no access permission anomaly for the access request.

[0023] Specifically, when the application is a front-end program and a proxy program is injected into the application, after the proxy program obtains the access request of the application, it can first detect whether the access request contains request parameters. If the access request does not contain request parameters, it indicates that the current access request does not involve database operations, so it can be determined that there is no access permission anomaly for the access request; if the access request contains request parameters, it indicates that the current access request may involve database operations, then the proxy program uploads the request parameters and user identification, and correspondingly, receives the request parameters and user identification for processing the access request by the application uploaded by the proxy program to further detect the access request; In addition, when the application is a back-end program and a proxy program is injected into the application, after the proxy program obtains the access request of the application, it can first detect whether the access request contains request parameters. If the access request does not contain request parameters, it indicates that the current access request does not involve database operations, so it can be determined that there is no access permission anomaly for the access request; if the access request contains request parameters, it indicates that the current access request may involve database operations, then it is necessary to obtain the request parameters and user identification for processing the access request by the application collected by the proxy program through step S202 to further detect the access request.

[0024] Step S204, determine whether the request parameters and the user identification are used as operation input parameters for performing the database operation corresponding to the access request.

[0025] In specific implementation, in the case where it has been detected that the request parameters have been used as operation input parameters for the database operation, in order to detect whether unauthorized data access has been performed in the database operation, so as to ensure that only authorized users can perform database operations on specific data, here, it is determined whether the request parameters and the user identification are simultaneously used as operation input parameters for performing the database operation, specifically, in the case where the request parameters have been used as operation input parameters for the database operation, it is determined whether the user identification has also been used as the operation input parameter for this database operation.

[0026] In a specific implementation process, in an optional implementation manner provided by this embodiment, after determining whether the request parameter and the user identifier are used as the operation input parameters for the database operation corresponding to the access request, the following steps are further included: If the operation input parameters for the database operation corresponding to the access request include the request parameter and the user identifier, it is determined that there is no access permission exception for the access request; If the operation input parameters for the database operation corresponding to the access request do not include the request parameter and / or the user identifier, step S206 is executed to query whether there is a data mapping relationship between the data table corresponding to the database operation and the user identifier, and perform a detection of permission verification on the database operation based on the detection policy corresponding to the query result.

[0027] Specifically, after determining whether the request parameter and the user identifier are used as the operation input parameters for the database operation, if the determination result is that the operation input parameters include the request parameter and the user identifier, it indicates that the database operation uses both the request parameter and the user identifier as the operation input parameters. Then, it can be considered that the request parameter and the user identifier are "bound", indicating that only users with corresponding permissions can access specific data in this case. Therefore, it can be determined that there is no access permission exception for the access request; If the determination result is that the operation input parameters do not include the request parameter and / or the user identifier, it indicates that the database operation uses only one of the request parameter or the user identifier as the operation input parameter, or the database operation does not use either the request parameter or the user identifier as the operation input parameter. In this case, there may be a situation of operating on the data of other users in the database, that is, it indicates that there is a risk of access permission exception for the access request. Then, it is necessary to query the data mapping relationship between the data table and the user identifier through step S206.

[0028] It should be noted that the process of determining whether the request parameter and the user identifier are used as the operation input parameters for the database operation corresponding to the access request can be replaced according to the actual processing needs as follows: determining whether the request parameter is used as the operation input parameter for the database operation corresponding to the access request; or, it can also be replaced by: determining whether the user identifier is used as the operation input parameter for the database operation corresponding to the access request.

[0029] Step S206: Query whether there is a data mapping relationship between the data table corresponding to the database operation and the user identifier, and perform a detection of permission verification on the database operation based on the detection policy corresponding to the query result.

[0030] During specific implementation, when the judgment result that the request parameter and the user identifier are used as the operation input parameters for executing the database operation corresponding to the access request is negative, first query whether there is a data mapping relationship between the data table corresponding to the database operation and the user identifier. After obtaining the query result, perform a detection of permission verification on the database operation based on the detection policy corresponding to the query result.

[0031] Specifically, during the process of querying whether there is a data mapping relationship between the data table corresponding to the database operation and the user identifier, it is possible to query whether there are fields or association relationships related to the user identifier in the data table corresponding to the database operation. For example, it is possible to query whether the data table directly contains the user identifier field, or it is also possible to query whether the data table has an association relationship with other data tables containing the user identifier field through a foreign key.

[0032] Optionally, the data mapping relationship includes: the user identifier is stored in the field of any data table in the database pointed to by the database operation, or the user identifier is stored in the field of the associated data table of any data table.

[0033] During the specific execution process, in order to achieve the purpose of controlling access permissions through other mechanisms even when the user identifier is not directly used in the database operation, in an optional implementation manner provided in this embodiment, querying whether there is a data mapping relationship between the data table corresponding to the database operation and the user identifier includes: Query whether there is a field corresponding to the user identifier in any data table in the database pointed to by the database operation; If so, determine that there is a data mapping relationship between the data table and the user identifier; If not, query whether the data table has an association relationship with the associated data table containing the user identifier. If there is an association relationship, determine that there is a data mapping relationship between the data table and the user identifier.

[0034] Among them, during the process of querying whether there is a data mapping relationship between the data table corresponding to the database operation and the user identifier, first query whether there are fields related to the user identifier in the data table involved in the database operation. If there are, it can be determined that there is a direct data mapping relationship between the data table and the user identifier. If not, it is necessary to further check whether the data table has an association relationship with other associated data tables containing the user identifier; if the query result of whether the data table has an association relationship with other associated data tables containing the user identifier is that there is an association relationship, it can be determined that there is an indirect data mapping relationship between the data table and the user identifier, otherwise, it is considered that there is no data mapping relationship between the data table and the user identifier.

[0035] In specific implementation, after querying whether there is a data mapping relationship between the data table corresponding to the database operation and the user identifier and obtaining the query result, the detection of permission verification for the database operation can be performed based on the detection policy corresponding to the query result. Specifically, the detection of permission verification for the database operation based on the detection policy corresponding to the query result means detecting whether the permission verification for the database operation has been performed based on the detection policy corresponding to the query result.

[0036] Among them, permission verification refers to verifying whether the user initiating the access request has the permission to perform a specific database operation or access specific data during the detection of access permission exceptions for the access request of the application program.

[0037] In the specific execution process, in an optional implementation manner provided in this embodiment, the detection of permission verification for the database operation includes: Obtain the operation result data for executing the database operation generated based on the request parameters; Extract multiple user identifier fields from the operation result data, and detect whether the user identifier is included in the multiple user identifier fields.

[0038] Specifically, after generating the corresponding database operation statement according to the request parameters in the access request and executing the corresponding database operation, obtain the operation result data and extract the field values related to the user identifier from the operation result data. For example, it can be the user identifier field directly stored in the current data table, or it can also be the user identifier field associated with other data tables through foreign keys, and then detect whether the user identifier of the current user is included in the extracted user identifier fields.

[0039] Optionally, the detection policy includes: a first detection policy corresponding to the query result of no data mapping relationship, and a second detection policy corresponding to the query result of existing data mapping relationship; among them, the first detection policy includes the detection of permission verification for the database operation, and the second detection policy includes not performing the detection of permission verification for the database operation.

[0040] In the specific execution process, in order to still effectively detect whether there is an access permission exception in the access request in the case of no data mapping relationship and improve the security of the access request, in an optional implementation manner provided in this embodiment, the detection of permission verification for the database operation based on the detection policy corresponding to the query result includes: If the query result is no data mapping relationship, detect whether the permission verification for the database operation has been performed; If the permission verification has been performed, determine that the access request has no access permission exception; If the permission verification has not been performed, determine that the access request has an access permission exception.

[0041] Specifically, in the case where no data mapping relationship exists between the data table corresponding to the database operation and the user identifier, it is further detected whether the database operation has been subjected to permission verification. If the permission verification has been performed, it indicates that even without a data mapping relationship, other means have been taken to verify that the database operation is secure, such as by means of permission verification. In this case, it can be determined that there is no access permission exception for the access request. If the permission verification has not been performed, it indicates that neither a data mapping relationship exists nor other means have been taken for permission verification. In this case, since it is impossible to determine that the database operation does not exceed the authority, it can be considered that the access request has an access permission exception.

[0042] In summary, in the method for detecting and processing exceptions of the application program provided in this embodiment, during the process of detecting and processing exceptions of the application program, the request parameters and the user identifier for processing the access request of the application program are obtained to provide a data basis for the subsequent detection process. Then, it is determined whether the request parameters and the user identifier are used as the operation input parameters for executing the database operation corresponding to the access request, so as to implement a preliminary judgment on whether there is permission control for the database operation. When at least one of the request parameters and the user identifier is not the operation input parameter of the database operation, it is queried whether the data table corresponding to the database operation has a data mapping relationship with the user identifier to determine whether there are other ways to ensure permission control. Finally, based on the detection strategy corresponding to the query result, the permission verification of the database operation is detected, thereby reducing the false negative rate and false positive rate of the detection of whether there is an access permission exception for the access request of the application program, and improving the accuracy of the exception detection for the access request.

[0043] The following takes the application of the exception detection method of an application program provided in this embodiment in a Web application scenario as an example, and in combination with Figure 3 , the exception detection method of the application program provided in this embodiment is further described. See Figure 3 , the exception detection method of the application program applied to the Web application scenario specifically includes the following steps.

[0044] Step S302: Receive the request parameters and the user identifier for processing the access request of the Web application.

[0045] Before step S302 is executed, the client obtains the access request of the Web application, and after obtaining the access request of the Web application, obtains the request parameters and the user identifier of the access request, and sends the request parameters and the user identifier to the server.

[0046] Step S304: Detect whether the request parameters are used as the operation input parameters of the database operation. If so, execute step S306; if so, determine that there is no access permission exception for the access request.

[0047] Step S306: Determine whether the request parameters and the user identifier are used as the operation input parameters for executing the database operation corresponding to the access request; if not, execute Step S308; if so, determine that there is no access permission exception for the access request.

[0048] Step S308: Query whether any data table in the database pointed to by the database operation has a field corresponding to the user identifier; if not, execute Step S310; if so, based on the second detection policy corresponding to the query result, do not perform the detection of the permission verification for the database operation.

[0049] Step S310: Query whether the data table has an association relationship with the associated data table containing the user identifier; if not, execute Step S312; if so, based on the second detection policy corresponding to the query result, do not perform the detection of the permission verification for the database operation.

[0050] Step S312: Based on the first detection policy corresponding to the query result, detect whether the permission verification for the database operation has been performed; if not, execute Step S314; if so, determine that there is no access permission exception for the access request.

[0051] Step S314: Determine that there is an access permission exception for the access request.

[0052] It should be noted that any one step or any combination of multiple steps from Step S302 to Step S314 can be combined with any one step or any combination of multiple steps from the above-mentioned Step S202 to Step S206 according to the needs of implementation and deployment to form a new implementation method; in addition, according to the actual deployment needs, any one or any combination of technical features from Step S302 to Step S314 can be combined with any one or more technical features provided by the above-mentioned Step S202 to Step S206 to form a new implementation method; or, any one or any combination of technical features from Step S302 to Step S314 can also be replaced by any one or more technical feature combinations provided by the above-mentioned Step S202 to Step S206 according to the actual deployment needs to form a new implementation method, which will not be elaborated here one by one.

[0053] The following takes the application of an exception detection method for an application program provided in this embodiment in the program exception detection scenario as an example, combined with Figure 4 , to further illustrate the exception detection method for the application program provided in this embodiment. Refer to Figure 4 , the exception detection method for the application program applied to the program exception detection scenario specifically includes the following steps.

[0054] Step S402: Obtain the request parameters and the user identifier for processing the access request of the program to be detected.

[0055] Step S404: Detect whether the request parameter is used as the query input parameter of the SQL statement. If not, execute Step S406; if so, determine that there is no access permission exception for the access request.

[0056] Step S406: Determine whether the request parameter and the user identifier are used as the query input parameters for executing the SQL statement corresponding to the access request. If not, execute Step S408; if so, determine that there is no access permission exception for the access request.

[0057] Step S408: Query whether any data table in the database pointed to by the SQL statement has a field corresponding to the user identifier. If not, execute Step S410; if so, based on the second detection policy corresponding to the query result, do not perform the detection of the permission verification for the SQL statement.

[0058] Step S410: Query whether the data table is associated with the associated data table containing the user identifier. If not, execute Step S412; if so, based on the second detection policy corresponding to the query result, do not perform the detection of the permission verification for the SQL statement.

[0059] Step S412: Based on the first detection policy corresponding to the query result, detect whether the permission verification for the SQL statement has been performed. If not, execute Step S414; if so, determine that there is no access permission exception for the access request.

[0060] Step S414: Determine that there is an access permission exception for the access request.

[0061] It should be noted that any one step or any combination of multiple steps from Step S402 to Step S414 can be combined with any one step or any combination of multiple steps from the above-mentioned Step S202 to Step S206 to form a new implementation manner according to the needs of implementation and deployment; in addition, according to the actual deployment needs, any one or any combination of technical features from Step S402 to Step S414 can be combined with any one or more technical features provided by the above-mentioned Step S202 to Step S206 to form a new implementation manner; or, any one or any combination of technical features from Step S402 to Step S414 can also be replaced by any one or more technical feature combinations provided by the above-mentioned Step S202 to Step S206 according to the actual deployment needs to form a new implementation manner, which will not be elaborated here one by one.

[0062] An embodiment of an abnormal detection device for an application program provided in this specification is as follows: In the above embodiment, an abnormal detection method for an application program is provided. Correspondingly, an abnormal detection device for an application program is also provided, which will be described below with reference to the accompanying drawings.

[0063] Refer to Figure 5, which shows a schematic diagram of an embodiment of an abnormal detection device for an application provided in this embodiment.

[0064] Since the device embodiment corresponds to the method embodiment, the description is relatively simple. For the relevant parts, please refer to the corresponding description of the method embodiment provided above. The device embodiments described below are merely illustrative.

[0065] This embodiment provides an abnormal detection device for an application. The device includes: A data acquisition module 502, configured to acquire request parameters and user identifiers for processing access requests of the application; the request parameters and the user identifiers are acquired by collecting through a proxy program injected into the application; An operation input parameter detection module 504, configured to determine whether the request parameters and the user identifiers are operation input parameters for executing a database operation corresponding to the access request; If not, run a permission verification detection module 506; The permission verification detection module 506 is configured to query whether there is a data mapping relationship between the data table corresponding to the database operation and the user identifier, and perform a detection of permission verification on the database operation according to the detection policy corresponding to the query result.

[0066] An embodiment of an abnormal detection device for an application provided in this specification is as follows: Corresponding to the above-described abnormal detection method for an application, based on the same technical concept, one or more embodiments of this specification also provide an abnormal detection device for an application. This abnormal detection device for an application is used to execute the above-provided abnormal detection method for an application. Figure 6 It is a schematic diagram of the structure of an abnormal detection device for an application provided by one or more embodiments of this specification.

[0067] An abnormal detection device for an application provided in this embodiment includes: Such as Figure 6As shown, the anomaly detection device of the application can vary significantly due to differences in configuration or performance. It can include one or more processors 601 and a memory 602. The memory 602 can store one or more applications or data. Among them, the memory 602 can be short-term storage or persistent storage. The applications stored in the memory 602 can include one or more modules (not shown in the figure), and each module can include a series of computer-executable instructions in the anomaly detection device of the application. Further, the processor 601 can be set to communicate with the memory 602 and execute a series of computer-executable instructions in the memory 602 on the anomaly detection device of the application. The anomaly detection device of the application can also include one or more power supplies 603, one or more wired or wireless network interfaces 604, one or more input / output interfaces 605, one or more keyboards 606, etc.

[0068] In a specific embodiment, the anomaly detection device of the application includes a memory and one or more programs. One or more of the programs are stored in the memory, and one or more of the programs can include one or more modules. Each module can include a series of computer-executable instructions in the anomaly detection device of the application and is configured to be executed by one or more processors. The one or more programs include computer-executable instructions for performing the following: Obtain the request parameters and user identification for the application to process the access request; the request parameters and the user identification are obtained by collecting through a proxy program injected into the application; Determine whether the request parameters and the user identification are the operation input parameters for executing the database operation corresponding to the access request; If not, query whether there is a data mapping relationship between the data table corresponding to the database operation and the user identification, and perform a detection of permission verification on the database operation according to the detection strategy corresponding to the query result.

[0069] An embodiment of the computer-readable storage medium provided in this specification is as follows: Corresponding to the above-described anomaly detection method of an application, based on the same technical concept, one or more embodiments of this specification also provide a computer-readable storage medium.

[0070] The computer-readable storage medium provided in this embodiment is used to store computer-executable instructions. When the computer-executable instructions are executed, the following process is implemented: Obtain the request parameters and user identification for the application to process the access request; the request parameters and the user identification are obtained by collecting through a proxy program injected into the application; Determine whether the request parameters and the user identifier are used as the operation input parameters for executing the database operation corresponding to the access request; If not, query whether there is a data mapping relationship between the data table corresponding to the database operation and the user identifier, and perform a detection of permission verification on the database operation according to the detection policy corresponding to the query result.

[0071] It should be noted that the embodiments of a computer-readable storage medium in this specification and the embodiments of an anomaly detection method for an application program in this specification are based on the same inventive concept. Therefore, the specific implementation of this embodiment can refer to the implementation of the corresponding method described above, and the repeated parts will not be elaborated.

[0072] An embodiment of a computer program product provided in this specification is as follows: Corresponding to the described anomaly detection method for an application program, based on the same technical concept, one or more embodiments of this specification also provide a computer program product.

[0073] A computer program product includes a computer program / instructions, and when the computer program / instructions are executed by a processor, the following steps are implemented: Obtain the request parameters and user identifier for the application program to process the access request; the request parameters and the user identifier are obtained by collecting through a proxy program injected into the application program; Determine whether the request parameters and the user identifier are used as the operation input parameters for executing the database operation corresponding to the access request; If not, query whether there is a data mapping relationship between the data table corresponding to the database operation and the user identifier, and perform a detection of permission verification on the database operation according to the detection policy corresponding to the query result.

[0074] It should be noted that the embodiments of a computer program product in this specification and the embodiments of an anomaly detection processing method for an application program in this specification are based on the same inventive concept. Therefore, the specific implementation of this embodiment can refer to the implementation of the corresponding method described above, and the repeated parts will not be elaborated.

[0075] The embodiments in this specification are all described in a progressive manner. The same or similar parts between the embodiments can be referred to each other. The key points of each embodiment are the differences from other embodiments. For example, the device embodiments, equipment embodiments, computer-readable storage medium embodiments, and computer program product embodiments are all similar to the method embodiments, so the descriptions are relatively simple. Please refer to the relevant descriptions in the method embodiments for reading the relevant content in the device embodiments, equipment embodiments, computer-readable storage medium embodiments, and computer program product embodiments.

[0076] The foregoing has described specific embodiments of the present specification. Other embodiments are within the scope of the appended claims. In some cases, the acts or steps recited in the claims may be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order shown or sequential order to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0077] In the 1930s, it was obvious to distinguish whether an improvement in a technology was a hardware improvement (e.g., improvement in circuit structures such as diodes, transistors, switches, etc.) or a software improvement (improvement in method processes). However, with the development of technology, many improvements in method processes today can be regarded as direct improvements in hardware circuit structures. Almost all designers obtain the corresponding hardware circuit structures by programming the improved method processes into the hardware circuits. Therefore, it cannot be said that an improvement in a method process cannot be implemented with hardware entity modules. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logical function is determined by the user's programming of the device. Designers can program by themselves to "integrate" a digital system on a single PLD, without having to ask a chip manufacturer to design and produce a dedicated integrated circuit chip. Moreover, nowadays, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented using "logic compiler" software, which is similar to the software compiler used in program development and writing. The original code before compilation also has to be written in a specific programming language, which is called a Hardware Description Language (HDL). There is not only one type of HDL, but many types, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones currently are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also be aware that as long as the method process is slightly logically programmed with the above-mentioned several hardware description languages and programmed into the integrated circuit, it is easy to obtain the hardware circuit that implements the logical method process.

[0078] The controller can be implemented in any suitable manner. For example, the controller can take the form of, for example, a microprocessor or a processor and a computer-readable medium storing computer-readable program code (such as software or firmware) executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of the controller include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that, in addition to implementing the controller in the form of pure computer-readable program code, it is entirely possible to logically program the method steps to enable the controller to be implemented in the form of logic gates, switches, application specific integrated circuits, programmable logic controllers, and embedded microcontrollers to achieve the same function. Therefore, such a controller can be considered a hardware component, and the devices included therein for implementing various functions can also be regarded as structures within the hardware component. Or even, the devices for implementing various functions can be regarded as either software modules for implementing the method or structures within the hardware component.

[0079] The systems, devices, modules, or units illustrated in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0080] For the convenience of description, when describing the above devices, they are described separately as various units according to their functions. Of course, when implementing the embodiments of this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0081] Those skilled in the art should understand that one or more embodiments of this specification can be provided as a method, a system, or a computer program product. Therefore, one or more embodiments of this specification can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, this specification can take the form of a computer program product implemented on one or more computer-readable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.

[0082] This specification is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the specification. It should be understood that each flow and / or block in the flowchart and / or block diagram, and combinations of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable interactive processing device in a live broadcast room to generate a machine, so that the instructions executed by the processor of the computer or other programmable interactive processing device in the live broadcast room generate means for implementing the functions specified in one Figure 1 flow or multiple flows and / or blocks Figure 1 or means for implementing the functions specified in one block or multiple blocks.

[0083] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable interactive processing device in a live broadcast room to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means implement the functions specified in one Figure 1 flow or multiple flows and / or blocks Figure 1 or means for implementing the functions specified in one block or multiple blocks.

[0084] These computer program instructions can also be loaded onto a computer or other programmable interactive processing device in a live broadcast room, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one Figure 1 flow or multiple flows and / or blocks Figure 1 or means for implementing the functions specified in one block or multiple blocks.

[0085] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.

[0086] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.

[0087] Computer-readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer-readable instructions, data structures, program modules or other data. Examples of computer-readable storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory media such as modulated data signals and carrier waves.

[0088] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of further restrictions, the elements defined by the sentence "includes at least one ..." do not exclude the presence of other identical elements in the process, method, commodity or device including the elements.

[0089] One or more embodiments of the present specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. One or more embodiments of the present specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.

[0090] The above description is only an embodiment of this document and is not intended to limit this document. For those skilled in the art, this document may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this document should be included in the scope of the claims of this document.

Claims

1. An abnormal detection method for an application program, comprising: Obtaining request parameters and user identifiers for processing access requests by the application program; The request parameters and the user identifiers are collected through a proxy program injected by the application program; Determining whether the request parameters and the user identifiers are operation input parameters for executing a database operation corresponding to the access request; If not, querying whether there is a data mapping relationship between the data table corresponding to the database operation and the user identifier, and performing a detection of permission verification on the database operation according to a detection strategy corresponding to the query result.

2. The abnormal detection method for the application program according to claim 1, the detection of performing permission verification on the database operation includes: Obtaining operation result data for executing the database operation generated based on the request parameters; Extracting multiple user identifier fields from the operation result data, and detecting whether the user identifier is included in the multiple user identifier fields.

3. The abnormal detection method for the application program according to claim 1, wherein the detection strategy includes: A first detection strategy corresponding to the query result of not having the data mapping relationship, and a second detection strategy corresponding to the query result of having the data mapping relationship; Wherein, the first detection strategy includes detecting the permission verification of the database operation, and the second detection strategy includes not detecting the permission verification of the database operation.

4. The abnormal detection method for the application program according to claim 3, the detection of performing permission verification on the database operation according to the detection strategy corresponding to the query result includes: If the query result is that there is no data mapping relationship, detecting whether the permission verification of the database operation has been performed; If the permission verification has been performed, determining that there is no access permission abnormality for the access request; If the permission verification has not been performed, determining that there is an access permission abnormality for the access request.

5. The abnormal detection method for the application program according to claim 1, after the step of determining whether the request parameters and the user identifiers are operation input parameters for executing the database operation corresponding to the access request, further comprising: If the operation input parameters of the database operation corresponding to the access request include the request parameters and the user identifier, determining that there is no access permission abnormality for the access request.

6. The abnormal detection method for the application program according to claim 1, the data mapping relationship includes: The user identifier is stored in a field of any data table in the database pointed to by the database operation, and / or, the user identifier is stored in a field of an associated data table of the any data table.

7. The abnormal detection method for the application program according to claim 1, the querying whether there is a data mapping relationship between the data table corresponding to the database operation and the user identifier includes: Querying whether there is a field corresponding to the user identifier in any data table in the database pointed to by the database operation; If so, determining that there is a data mapping relationship between the data table and the user identifier; If not, query whether there is an association relationship between the data table and the associated data table containing the user identifier. If there is such an association relationship, determine that there is such a data mapping relationship between the data table and the user identifier.

8. The method for detecting anomalies in an application according to claim 1, wherein the application includes a Web application; the proxy program obtains the stack data of the application, and reads and uploads the request parameters and the user identifier from the stack data.

9. The method for detecting anomalies in an application according to claim 1, after the step of obtaining the request parameters and the user identifier for processing the access request of the application is executed, and before the step of determining whether the request parameters and the user identifier are used as the operation input parameters for executing the database operation corresponding to the access request, further includes: Detect whether the request parameter is used as the operation input parameter for the database operation; If not, determine that there is no access permission anomaly for the access request; If so, execute the step of determining whether the request parameters and the user identifier are used as the operation input parameters for executing the database operation corresponding to the access request.

10. The method for detecting anomalies in an application according to claim 1, before the step of obtaining the request parameters and the user identifier for processing the access request of the application is executed, further includes: Detect whether the access request contains the request parameter; If the request parameter is included, execute the step of obtaining the request parameters and the user identifier for processing the access request of the application; If the request parameter is not included, determine that there is no access permission anomaly for the access request.

11. An apparatus for detecting anomalies in an application, including: A data acquisition module configured to obtain request parameters and a user identifier for processing an access request of an application; The request parameters and the user identifier are obtained by collecting through a proxy program injected by the application; An operation input parameter detection module configured to determine whether the request parameters and the user identifier are used as the operation input parameters for executing the database operation corresponding to the access request; If not, run the permission verification detection module; The permission verification detection module is configured to query whether there is a data mapping relationship between the data table corresponding to the database operation and the user identifier, and perform a permission verification detection on the database operation according to the detection strategy corresponding to the query result.

12. An apparatus for detecting anomalies in an application, including: A processor; And a memory configured to store computer-executable instructions, the computer-executable instructions, when executed, cause the processor to: Obtain request parameters and a user identifier for processing an access request of an application; the request parameters and the user identifier are obtained by collecting through a proxy program injected by the application; Determine whether the request parameters and the user identifier are used as the operation input parameters for executing the database operation corresponding to the access request; If not, query whether there is a data mapping relationship between the data table corresponding to the database operation and the user identifier, and perform a permission verification detection on the database operation according to the detection strategy corresponding to the query result.

13. A computer-readable storage medium for storing computer-executable instructions, which, when executed, implement the steps of the method recited in claim 1.