Method and device for detecting abnormal behavior of application program control
By extracting interface and code semantic features from the application package, generating a complete program call graph and performing cluster analysis, the problems of high false positive rate and poor interpretation in the existing technology are solved, and precise detection and security enhancement of application control behavior are achieved.
Patent Information
- Application Number
- CN202510192981.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-20
- Publication Date
- 2025-07-22
AI Technical Summary
In the prior art, application analysis methods based on code level have problems such as high false positive rate, poor interpretability and narrow application, and it is difficult to accurately detect abnormal behavior of application controls.
By extracting the interface and code semantic features in the application package, a complete program call diagram is generated, the code context of the control trigger event is accurately locked, the subgraphs implemented by specific functions are divided, and the subgraphs are encoded and vectorized, and clustered analysis is performed in combination with the interface semantic features to detect abnormal behavior.
It improves the accuracy and interpretability of application control behavior analysis, reduces false positive rates, enhances the security and reliability of mobile applications, and adapts to a variety of application scenarios.
Smart Images

Figure CN120354408A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and particularly to a method and device for detecting abnormal behavior of application program controls. Background Art
[0002] In related technologies, the analysis methods for malicious behaviors of application programs (hereinafter having the same meaning as applications) mainly focus on information at the application code level, such as API (Application Programming Interface) calls, method call graphs, data flows, and permission declarations, and rely on sensitive API or permission lists.
[0003] However, with the continuous increase in the functions integrated in applications and the presentation of personalized customized content for specific users, the calls of applications to sensitive APIs or permissions are increasing day by day. At the same time, there is still a lack of unified and authoritative consensus on the sensitive APIs or permission lists used as the basis for behavior analysis and determination. As a result, the analysis results highly depend on the quality of the selected domain knowledge and generate a large number of false alarms. Moreover, since the determination results provided to security analysts only contain information at the code level, security analysts also need to combine other information of the application to confirm whether the reported results are accurate with extra labor. In addition, binary determination or classification of specific families is difficult to be automatically applied and extended to new or application families with a limited number of in-the-wild application samples. In summary, the analysis method based only on the code level in related technologies has problems such as a high false alarm rate, poor interpretability, and narrow applicability. Summary of the Invention
[0004] This application provides a method and device for detecting abnormal behavior of application program controls to solve the problems in related technologies, such as the analysis method based only on the code level having a high false alarm rate, poor interpretability, and narrow applicability.
[0005] The first aspect of the embodiments of this application provides a method for detecting abnormal behavior of application program controls, including the following steps: extracting the interface semantic features and code semantic features in a preset application program package, and generating a complete program call graph of the code in the application program package based on the code semantic features; determining the code context of the trigger event of the application program control according to the complete program call graph; dividing the complete program call graph based on the code context of the trigger event of the application program control to generate a subgraph for the specific function implementation of the trigger event of the application program control; encoding the underlying implementation instructions of each method included in the subgraph to obtain an encoded subgraph, and vectorizing the encoded subgraph to obtain the representation information of the behavior of the application program control in the vector space, and performing clustering analysis based on the representation information to obtain the abnormal behavior detection result of the application program control in combination with the interface semantic features.
[0006] Through the above technical solutions, the embodiments of the present application can extract the interface and code semantic features from the application package, generate a complete program call graph, accurately lock the code context of the control trigger event, and divide the subgraphs that implement specific functions accordingly. Encode and vectorize the underlying instructions of the subgraphs to obtain the representation information of the vector space, and then combine the interface semantic feature clustering analysis to accurately detect the abnormal behaviors of the application controls, without relying on specific prior knowledge, adapting to various application scenarios, and effectively solving the problems of high false alarm rate, poor interpretability, and narrow application scope of traditional methods.
[0007] Optionally, in an embodiment of the present application, the extraction of the interface semantic features in the preset application package includes: parsing the application interface list declared in the application manifest in the application package; parsing the binary resource mapping list in the application package to obtain the appearance attribute values corresponding to the controls, and in the case where the appearance attribute values of the application controls do not exist, using the preset static code to supplement the missing appearance attribute values of the application controls; parsing the interface layout defined in the layout file in the application package, the inclusion relationship between the control attributes and the sub-layouts; and obtaining the interface semantic features according to the application interface list, the appearance attribute values, the interface layout, and the inclusion relationship between the control attributes and the sub-layouts.
[0008] Through the above technical solutions, the embodiments of the present application can comprehensively parse the application manifest, the binary resource mapping list, and the layout file by extracting the interface semantic features in the application package, so as to obtain the appearance attribute values of the controls and their layout relationships. When the appearance attribute values of the controls are missing, static code is used for supplementation, ensuring the integrity and accuracy of the control features. The accuracy of the interface semantic features is improved, providing a more reliable basis for subsequent application behavior analysis.
[0009] Optionally, in an embodiment of the present application, the extraction of the code semantic features in the preset application package and the generation of a complete program call graph of the code in the application package based on the code semantic features include: performing code decompilation on the code in the application package to obtain the decompiled code; performing control flow analysis on the decompiled code to obtain the code semantic features, and generating the complete program call graph according to the code semantic features.
[0010] Through the above technical solutions, the embodiments of the present application can efficiently and accurately extract the semantic features of the code by decompiling and performing control flow analysis on the code, so as to generate a complete program call graph. It not only improves the ability to understand and analyze the behavior of the application program, but also can effectively reduce the false alarm rate and enhance the interpretability of the code analysis.
[0011] Optionally, in an embodiment of the present application, dividing the complete program call graph based on the code context of the trigger event of the application control to generate a sub-graph of the specific function implementation of the trigger event of the application control includes: performing a callback starting from the trigger event of the application control, searching for subsequent code contexts in the complete program call graph to generate multiple first sub-graphs, and forming a candidate set for the specific function implementation of the trigger event of the application control with the call codes of each method in the first sub-graph; performing data flow analysis and code block analysis on the candidate set to exclude codes that are unreachable during actual operation; and based on the unreachable codes, trimming the first sub-graph to obtain a sub-graph of the specific function implementation of the trigger event of the application control.
[0012] Through the above technical solution, the embodiment of the present application can accurately divide the complete program call graph based on the code context of the trigger event of the application control to generate a sub-graph of the specific function implementation of the control trigger event. It can not only identify the candidate set of the control function, but also exclude codes that are unreachable during actual operation through analysis, thereby improving the accuracy and interpretability of function implementation and reducing the false alarm rate.
[0013] Optionally, in an embodiment of the present application, performing clustering analysis based on the characterization information to obtain the behavior anomaly detection result of the application control in combination with the interface semantic features includes: using clustering analysis to detect the interface semantics of the application control and the sub-graph of the specific function implementation of the trigger event. When the interface semantics are inconsistent with the sub-graph of the specific function implementation of the trigger event, marking the application control as abnormal; and reporting the sub-graph of the specific function implementation of the trigger event of the marked abnormal application control to a security analyst for the security analyst to check and repair the application package.
[0014] Through the above technical solution, the embodiment of the present application can detect the behavior anomaly of the application control through clustering analysis and in combination with the interface semantic features. When the interface semantics are inconsistent with the sub-graph of the specific function implementation of the trigger event, the system can accurately mark the control as abnormal and report the relevant information to the security analyst. It not only improves the accuracy of anomaly detection and reduces the false alarm rate, but also provides a clear repair basis for the security analyst, enhancing the security and reliability of the mobile application.
[0015] According to a second aspect embodiment of the present application, a device for detecting abnormal behavior of application program controls is provided, including: an extraction module, configured to extract interface semantic features and code semantic features within a preset application program package, and generate a complete program call graph of the code within the application program package based on the code semantic features; a determination module, configured to determine the code context of the trigger event of the application program control according to the complete program call graph; a division module, configured to divide the complete program call graph based on the code context of the trigger event of the application program control to generate a sub-graph for implementing the specific function of the trigger event of the application program control; a detection module, configured to encode the underlying implementation instructions of each method included in the sub-graph to obtain an encoded sub-graph, vectorize the encoded sub-graph to obtain the representation information of the behavior of the application program control in the vector space, and perform clustering analysis based on the representation information to obtain the abnormal behavior detection result of the application program control in combination with the interface semantic features.
[0016] Through the above technical solution, the embodiments of the present application can extract interface and code semantic features from the application program package, generate a complete program call graph, accurately lock the code context of the control trigger event, and divide the sub-graph for implementing the specific function accordingly. By encoding and vectorizing the underlying instructions of the sub-graph, the representation information in the vector space is obtained, and then clustering analysis is combined with the interface semantic features to accurately detect the abnormal behavior of the application program control, without relying on specific prior knowledge, adapting to various application scenarios, and effectively solving the problems of high false alarms, poor interpretability, and narrow applicability of traditional methods.
[0017] Optionally, in an embodiment of the present application, the extraction module includes: a first parsing unit, configured to parse the application interface list declared in the application manifest in the application program package; a second parsing unit, configured to parse the binary resource mapping list in the application program package to obtain the control and its corresponding appearance attribute value, and in the case where the appearance attribute value of the application program control does not exist, use preset static code to supplement the missing appearance attribute value of the application program control; a third parsing unit, configured to parse the interface layout defined in the layout file in the application program package, the inclusion relationship between the control attributes and the sub-layouts; an obtaining unit, configured to obtain the interface semantic features according to the application interface list, the appearance attribute value, the interface layout, and the inclusion relationship between the control attributes and the sub-layouts.
[0018] Through the above technical solution, the embodiment of the present application can extract the interface semantic features in the application package, comprehensively analyze the application manifest, binary resource mapping list and layout file, so as to obtain the appearance attribute values of the controls and their layout relationships. When the appearance attribute values of the controls are missing, static code is used for supplementation to ensure the integrity and accuracy of the control features. The accuracy of the interface semantic features is improved, providing a more reliable basis for subsequent application behavior analysis.
[0019] Optionally, in an embodiment of the present application, the extraction module includes: a decompilation unit for performing code decompilation on the code in the application package to obtain the decompiled code; a control flow analysis unit for performing control flow analysis on the decompiled code to obtain the code semantic features and generating the complete program call graph according to the code semantic features.
[0020] Through the above technical solution, the embodiment of the present application can efficiently and accurately extract the semantic features of the code through decompilation and control flow analysis of the code, so as to generate a complete program call graph. It not only improves the ability to understand and analyze the behavior of the application program, but also can effectively reduce the false alarm rate and enhance the interpretability of code analysis.
[0021] Optionally, in an embodiment of the present application, the partitioning module includes: a generating unit for performing a callback starting from the trigger event of the application control, searching for subsequent code contexts in the complete program call graph to generate a plurality of first subgraphs, and forming a candidate set for the specific function implementation of the trigger event of the application control by the call codes of each method in the first subgraph; an analyzing unit for performing data flow analysis and code block analysis on the candidate set to exclude the codes that are unreachable during actual operation in the candidate set; a pruning unit for pruning the first subgraph based on the unreachable codes to obtain a subgraph for the specific function implementation of the trigger event of the application control.
[0022] Through the above technical solution, the embodiment of the present application can accurately partition the complete program call graph based on the code context of the trigger event of the application control, and generate a subgraph for the specific function implementation of the control trigger event. It can not only identify the candidate set of the control function, but also exclude the codes that are unreachable during actual operation through analysis, thereby improving the accuracy and interpretability of the function implementation and reducing the false alarm rate.
[0023] Optionally, in an embodiment of the present application, the detection module includes: a clustering analysis unit, configured to detect, by using clustering analysis, a sub-graph of the interface semantics of the application program control and the specific function implementation of the trigger event, and mark the application program control as abnormal in the case where the interface semantics is inconsistent with the sub-graph of the specific function implementation of the trigger event; an abnormal reporting unit, configured to report the sub-graph of the specific function implementation of the trigger event of the application program control marked as abnormal to a security analyst, so as to facilitate the security analyst to troubleshoot and repair the application program package.
[0024] Through the above technical solution, the embodiment of the present application can detect the abnormal behavior of the application program control by clustering analysis and combining the interface semantic features. When the interface semantics is inconsistent with the sub-graph of the specific function implementation of the trigger event, the system can accurately mark the control as abnormal and report the relevant information to the security analyst. This not only improves the accuracy of abnormal detection and reduces the false alarm rate, but also provides a clear repair basis for the security analyst, enhancing the security and reliability of the mobile application.
[0025] An embodiment of the third aspect of the present application provides an electronic device, including: a memory, a processor, and a computer program stored on the memory and executable on the processor, where the processor executes the program to implement the method for detecting the abnormal behavior of the application program control as described in the above embodiment.
[0026] An embodiment of the fourth aspect of the present application provides a computer-readable storage medium, where the computer-readable storage medium stores a computer program, and when the program is executed by a processor, the method for detecting the abnormal behavior of the application program control as described above is implemented.
[0027] An embodiment of the fifth aspect of the present application provides a computer program product, where the computer program is executed to implement the method for detecting the abnormal behavior of the application program control as described above.
[0028] The embodiment of the present application can comprehensively extract the semantic features of the interface and the code from the application program package, generate a complete program call graph, and accurately lock the code context of the control trigger event, so as to divide the sub-graph for implementing the specific function. By parsing the application manifest, the binary resource mapping list, and the layout file, the integrity and accuracy of the control appearance attributes are ensured, thereby improving the accuracy of the interface semantic features and providing a reliable basis for subsequent application behavior analysis. At the same time, through decompilation and control flow analysis, the understanding and analysis ability of the application program behavior are improved, effectively reducing the false alarm rate and enhancing the interpretability. In addition, combined with clustering analysis, the abnormal behavior of the application program control can be accurately detected. When the interface semantics is inconsistent with the specific function implementation, the system can accurately mark the abnormality and report it to the security analyst, providing a clear repair basis and enhancing the security and reliability of the mobile application.
[0029] Additional aspects and advantages of the present application will be given in part in the following description, become apparent in part from the following description, or be learned through the practice of the present application. Description of the Drawings
[0030] The above-mentioned and / or additional aspects and advantages of the present application will become apparent and be readily understood from the following description of embodiments in conjunction with the drawings, where:
[0031] Figure 1 is a flowchart of a method for detecting abnormal behavior of application program controls provided according to an embodiment of the present application;
[0032] Figure 2 is a schematic structural diagram of a device for detecting abnormal behavior of application program controls provided according to an embodiment of the present application;
[0033] Figure 3 is a schematic structural diagram of an electronic device provided according to an embodiment of the present application. Detailed Embodiments
[0034] Embodiments of the present application will be described in detail below. Examples of the embodiments are shown in the drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the drawings are exemplary and are intended to explain the present application and should not be construed as limiting the present application.
[0035] The method and device for detecting abnormal behavior of application program controls according to embodiments of the present application will be described below with reference to the drawings. In view of the problems of high false alarm rate, poor interpretability, narrow application scope, etc. existing in the analysis method based only on the code level in the related art mentioned in the above background art, the present application provides a method for detecting abnormal behavior of application program controls. In this method, interface and code semantic features can be extracted from the application program package to generate a complete program call graph, accurately lock the code context where the control triggers an event, and divide subgraphs that implement specific functions accordingly. Encode and vectorize the underlying instructions of the subgraphs to obtain the characterization information of the vector space, and then combine the interface semantic feature clustering analysis to accurately detect the abnormal behavior of the application program controls, without relying on specific prior knowledge and adapting to a variety of application scenarios. Thus, the problems of high false alarm rate, poor interpretability, narrow application scope, etc. existing in the analysis method based only on the code level in the related art are solved.
[0036] Specifically, Figure 1 is a schematic flowchart of a method for detecting abnormal behavior of application program controls provided according to an embodiment of the present application.
[0037] As Figure 1 shown, the method for detecting abnormal behavior of application program controls includes the following steps:
[0038] In step S101, the interface semantic features and code semantic features in a preset application package are extracted, and a complete program call graph of the code in the application package is generated based on the code semantic features.
[0039] It should be noted that the preset application package in this application can be an Android application. Since the Android system is the most popular mobile operating system at home and abroad as of 2025, this application selects the most representative and universal Android application description method and process, which is not a limitation to this application, and other application packages can also be selected.
[0040] Optionally, in an embodiment of this application, extracting the interface semantic features in a preset application package includes: parsing the application interface list declared in the application manifest in the application package; parsing the binary resource mapping list in the application package to obtain the appearance attribute values corresponding to the controls, and in the case where the application control does not have an appearance attribute value, using preset static code to supplement the missing appearance attribute values of the application control; parsing the interface layout, control attributes, and inclusion relationships of sub-layouts defined in the layout files in the application package; obtaining the interface semantic features according to the application interface list, appearance attribute values, interface layout, control attributes, and inclusion relationships of sub-layouts.
[0041] Specifically, in the actual execution process, an application package in the APK format can be used as the input to parse the binary file after encoding the application resources. The application resources can be ARSC (Android Resource Packaging Library), and a static resource "type - name - identifier" mapping table is extracted from it. For example, considering the characteristics that mobile applications usually decouple different types of static resources and index and search them through codes, when parsing the appearance semantics of a button type control c with the text attribute set to "@string / btn_user_log_in", the string value corresponding to the string resource named "btn_user_log_in" is searched in the ARSC resource table. If there is, it is recorded as the text that the button c will actually display during the application run. If not, an attempt is made to extract the attribute value set in the code based on code analysis in the subsequent code analysis step S102.
[0042] Furthermore, all layout files are parsed. For each layout file, its tree nodes are traversed to parse the appearance attributes of the controls, including the identifier id, text, prompt information, image source, etc. When the tree node passes through <include>When importing other layouts with tags such as this, expand the corresponding sub-layouts to determine all the controls included in a layout and to determine on which layout a certain control is displayed during the operation of the application.
[0043] Optionally, in an embodiment of the present application, code semantic features in a preset application package are extracted, and a complete program call graph of the code in the application package is generated based on the code semantic features, including: performing code decompilation on the code in the application package to obtain the decompiled code; performing control flow analysis on the decompiled code to obtain the code semantic features, and generating a complete program call graph according to the code semantic features.
[0044] It can be understood that in the code logic level analysis of mobile applications, what is faced is a binary executable file formed after a series of complex processes such as compilation, translation, refactoring, compression, and packaging. This is the basis for a mobile application to be read and run on a specific mobile operating system. In order to deeply understand the internal code structure and operation mechanism of the application, it is necessary to perform a decompilation operation on this binary executable file.
[0045] Through decompilation, each class of the program can be parsed from the binary file, as well as the method call situations included in each class. At the same time, relevant program control flow and data flow information can also be obtained. The control flow reflects the execution order and logical direction of the program, while the data flow shows the transfer path of data in the program.
[0046] It should be noted that mobile applications have a unique life cycle management mechanism. Different from traditional programs, it does not have a clear entry point like the Main function. During the operation of a mobile application, several implicitly or asynchronously called methods defined by the mobile application framework may all become the actual entry point of the program. For example, when the application resumes from the suspended state to the foreground, the corresponding callback method may trigger a series of operations of the program, thus becoming the starting point of program execution.
[0047] In view of the above special situation, the embodiment of the present application adopts a method of generating a virtual program entry point. By deeply studying the life cycle of the application and its components (such as user interface windows), the control flow existing during different state transitions of the application can be accurately determined. Based on this control flow information, a connected and complete mobile application CG (Call Graph) is further constructed, represented by the symbol In this call graph, each node represents a method, and the directed edges between the nodes clearly represent the call relationships between the methods. Such a call graph can intuitively reflect the code context between program processes and provide strong support for subsequent analysis and understanding of the application program.
[0048] Embodiments of this application can extract the interface semantic features and code semantic features within an Android application package, and generate a complete program call graph based on these features. Specifically, the interface semantic features are obtained by parsing the application manifest, binary resource mapping, and layout files to acquire the appearance attributes of controls and their relationships, while the code semantic features are constructed by decompiling the code within the application package and performing control flow analysis to build the call graph. This method can not only deeply understand the internal structure and operation mechanism of the application, but also accurately reflect the relationship between controls and their functions, providing comprehensive data support for subsequent security analysis, thereby improving the accuracy and interpretability of application behavior analysis.
[0049] In step S102, determine the code context of the trigger event of the application control according to the complete program call graph.
[0050] During the actual execution process, identify the search and reference to interface controls in the code. Through careful examination of the code, find the parts in the code that search for and reference interface controls. In this process, variable tracking as needed is a key operation, which can help accurately record the method calls containing control references and the controls being referenced. At the same time, also identify the branches in the code and extract the corresponding relationship between the controls and the branch logic. These information provide important basis for subsequent further analysis of events triggered by controls and operations such as setting the appearance attributes of controls.
[0051] Furthermore, conduct customized static code analysis to accurately locate the events triggered by controls, identify the settings of control appearance attributes in the code, and analyze the code blocks reachable by each control.
[0052] Specifically, this code analysis is implemented based on three-address code. As an intermediate language for writing source code languages such as Java used in mobile applications, three-address code has the characteristics of high efficiency and clearly representing the execution logic of high-level languages, facilitating program analysis tasks such as data flow analysis. It should be noted that during the process of converting source code to three-address code, to improve the code conversion efficiency, program variable names will be simplified and reallocated, and at the same time, reusable intermediate (temporary) variable names are introduced. For example, the source code statement stat:=(Imageview)layout.findViewByID(viewID) will be split into two three-address code statements, corresponding to the operations of obtaining an intermediate variable through a findViewByID call and casting the intermediate variable to a control instance of a specific type (such as Imageview) through forced type conversion. For performance improvement considerations, intermediate variables can be used by multiple controls during the decompilation process. For example, during the initialization of the application user interface, the onCreate method is overloaded, and multiple controls w1, w2,……, w are continuously assigned values in it n , By the above source code statements, extracting specific controls in the layout and assigning them to a control variable is a common practice in mobile application development. At this time, w1, w2, ……, w n will share the same intermediate variable. Although the decompilation process can preserve the data flow transfer in the original code, it simultaneously causes the code analysis based on the forward reachability analysis of variables to be unable to accurately locate the variable transfer relationship, generating a large number of incorrect data flows. For example, even if the controls w1, w2, ……, w n are respectively bound to different event callbacks e1, e2, ……, e n Since they all share the intermediate variable, and this intermediate variable forms a reachable data flow with all event callbacks, each control in w1, w2, ……, w n will be incorrectly connected to all n click callbacks in e1, e2, ……, e n .
[0053] To solve the above problems, the embodiments of the present application can identify the call points of all set event callbacks in the code. For each call point, trace back the data flow of the corresponding parameters from back to front until the class of an event callback is determined. Compared with the existing program analysis methods based on forward data flow tracing or variable reachability, it not only avoids the large performance overhead caused by the need to analyze the reachability of all variable names in advance by the method based on variable reachability, but also can accurately bind the control to the event it triggers.
[0054] In some other embodiments, similar data flow tracing means are adopted to trace the variables related to the call at the method call points for setting control appearance attributes including but not limited to setting text, setting title, setting hint text, and setting image source. In this way, the incoming parameter values of the method call can be used to replace the missing corresponding control appearance attributes in the static layout definition. For example, when the text displayed by a button is not defined or is a default value in the static layout file, if it is recognized that the code contains a method call for setting text, the specific text content that the button will display during the application runtime can be determined, so as to more accurately understand the actual function and display effect of the control.
[0055] To further avoid the code context that can be triggered by the control from incorrectly including code that is unreachable during the actual operation of the application, each method call can be delved into and divided into one or more code blocks. Each method of the application may contain code branches and multi-threaded calls, and different branches or threads correspond to different entry conditions. For example, several controls on the same user interface can share a click event. After the user clicks, check the control Id that the user is currently interacting with. When it is equal to a specific value, different subsequent code operations are respectively executed. To obtain the set of all code blocks By traversing the code downward from each branch label until a code control flow statement is encountered or the last statement of the method is reached, all statements involved in the traversal process are marked as belonging to the same code block. Thus, it is clear under what conditions (i.e., the control Id triggering the current code is equal to a specific value) the application will execute the statements in the corresponding code block, thereby more accurately analyzing the code logic triggered by the control.
[0056] Embodiments of the present application can identify the code context of the trigger events of application controls through the analysis of the complete program call graph, accurately track the search and reference of interface controls in the code. Through careful review and variable tracking, accurately record the method calls referenced by the control and their corresponding controls, and at the same time extract the logical relationship between the control and the code branch. It not only improves the recognition accuracy of the control appearance attribute settings, but also provides an important basis for subsequent analysis. Using three-address code for code analysis ensures an efficient representation of the execution logic of high-level languages, and through data flow backtracking means, accurately bind controls to events, avoiding false alarms and performance overhead, and thus enhancing the interpretability and accuracy of control functions.
[0057] In step S103, based on the code context of the trigger events of application controls, divide the complete program call graph to generate a subgraph of the specific function implementation of the trigger events of application controls.
[0058] It can be understood that the complete program call graph covers the call relationships between all methods in the application. The purpose of step S103 is to cut out the subgraph belonging to each control event in this complex call graph, that is, the subgraph of the specific function implementation, to clearly analyze the code logic and execution path behind each control event.
[0059] Optionally, in an embodiment of the present application, based on the code context of the trigger events of application controls, divide the complete program call graph to generate a subgraph of the specific function implementation of the trigger events of application controls, including: starting from the trigger event of the application control for callback, searching for subsequent code contexts in the complete program call graph to generate multiple first subgraphs, and forming a candidate set for the specific function implementation of the trigger events of the application control by the call codes of each method in the first subgraph; performing data flow analysis and code block analysis on the candidate set to exclude the codes that are unreachable in actual operation; based on the unreachable codes, trimming the first subgraph to obtain the subgraph of the specific function implementation of the trigger events of the application control.
[0060] Specifically, extract the connected subgraph starting from the event callback method e triggered by the control in the call graph obtained in step S101 in the Each method in the figure constitutes a candidate set for the specific function implementation of the control In not all methods can be triggered by the current control. Therefore, perform data flow analysis and code block analysis on the candidate set, and traverse all sets of code blocks that are unreachable by the current control w For all method calls involved therein For each method c in further determine whether it can definitely be triggered by w: If the determination is true, retain the method to avoid the situation where c is reused in other constantly reachable code blocks (i.e., without trigger conditions or trigger conditions that are always true), but is wrongly excluded from the functional implementation context of w. Accordingly, perform pruning on the connected subgraph The code context that can ultimately represent the functional implementation of w should be a connected subgraph on and starting from the starting point w of where the node set consists of several method calls: The edge set ε is all directed edges between these nodes.
[0061] Embodiments of the present application can partition the complete program call graph based on the code context of the application control trigger event, thereby generating a subgraph for the specific function implementation of each control event. Extracting the code logic and execution path related to a specific control event from the complex call relationship ensures that the function implementation of the control can be clearly analyzed, the specific code logic behind the control event can be accurately identified, the false positive rate can be reduced, the interpretability of the analysis can be improved, and at the same time, false judgments caused by the interference of unreachable code can be avoided, thereby providing a more reliable basis for security analysis.
[0062] In step S104, encode the underlying implementation instructions of each method included in the subgraph to obtain an encoded subgraph, and vectorize the encoded subgraph to obtain the representation information of the behavior of the application control in the vector space. Perform clustering analysis based on the representation information to obtain the behavior anomaly detection result of the application control in combination with the interface semantic features.
[0063] During the actual execution process, perform clustering analysis based on the representation information to obtain the behavior anomaly detection result of the application control in combination with the interface semantic features, including: using clustering analysis to detect the interface semantics of the application control and the subgraph for the specific function implementation of the trigger event. In the case where the interface semantics are inconsistent with the subgraph for the specific function implementation of the trigger event, mark the application control as abnormal; report the subgraph for the specific function implementation of the trigger event of the application control marked as abnormal to the security analyst for the security analyst to conduct troubleshooting and repair of the application package.
[0064] The underlying implementation instructions of each method in the subgraph obtained in step S103 are encoded to extract its code functions. Specifically, opcodes are used to encode each node, which corresponds to a specific method. Compared with traditional program semantic analysis techniques, the latter usually rely on names in the form of strings such as method signatures and class names, which are often affected by obfuscation or overloading techniques in mobile applications, resulting in the inability to accurately represent the functional semantics of the code. For example, obfuscation technology may rename an originally clear function name (such as send_message) to a string with no clear meaning (such as axz) during compilation, making the analysis work complicated.
[0065] In this context, opcodes, as the basic building blocks of method implementation, can reflect the fine-grained program behavior of method execution, including but not limited to register operations, control flow operations, etc. There are 264 different opcodes in the Android system. In one embodiment of the present application, each method can be encoded with a vector of length 264. When a method uses a specific opcode, the corresponding element in the vector is set to 1; if it is not used, the element is 0. This encoding method ensures that methods with similar functions have similar representations in the vector space, thereby effectively avoiding interference caused by source code protection techniques such as obfuscation or overloading.
[0066] Furthermore, the encoded subgraph is vectorized to obtain the representation of the control behavior in the vector space, and cluster analysis is performed to detect the inconsistency between the interface-level semantics and the code function-level semantics, thereby identifying abnormal application controls. Specifically, the graph structure data is embedded into a vector space as input. This graph not only contains multiple nodes (such as the semantics of the method implementation based on the opcode), but also includes important structural information that reveals the complex relationships and interactions between the entities in the graph (such as the method call relationship).
[0067] By aggregating the node features, neighborhood information, and overall graph structure information of the graph, techniques including but not limited to spectral operations and graph neural networks can be used to calculate the vectorized representation of the control function implementation graph. Taking the "Login" button as an example, in one embodiment of the present application, the function implementation graphs of this type of control from multiple mobile applications are extracted and the corresponding vectorized representations are generated. Subsequently, through cluster analysis and by selecting a suitable clustering algorithm, such as including but not limited to the K-Means algorithm, hierarchical clustering algorithm, etc., controls with similar functions are grouped together. Taking the K-Means algorithm as an example, first, the number of clustering categories K needs to be determined. The value of K can be determined based on experience or multiple trials. Based on the preliminary understanding of the "Login" button function and past security analysis experience, K can be set to 3, which can be typical, benign, and abnormal. If a "Login" button is not classified into the typical or benign "Login" button category, this control will be marked as possibly performing unexpected abnormal behavior. At the same time, the security analyst will receive an alert and can further analyze the function implementation graph of this control. For example, after the "Login" button is clicked, it may trigger the behavior of uploading the user's login credentials to the malware developer via email. By extracting the minimum function implementation subgraph of this button and encoding the underlying implementation of each method in the graph based on the opcode, it can be found that this graph does not conform to the control behavior category of a typical or benign login button. Therefore, the security analyst can detect and fully explain potential phishing and other malicious behaviors in the application in a timely manner, thereby enhancing the security of the mobile application.
[0068] In the embodiment of the present application, the underlying implementation instructions of each method in the subgraph can be opcode-encoded to generate an encoded subgraph, and further vectorized to obtain the representation information of the control behavior in the vector space. Combining with the interface semantic features for cluster analysis, the behavior anomaly detection of the application program controls can be realized. When the interface semantics is inconsistent with the specific function implementation of the triggered event, the control will be marked as abnormal and reported to the security analyst for repair. Among them, the opcode encoding can accurately reflect the fine-grained behavior of the method, avoiding the semantic ambiguity caused by confusion or overloading in traditional analysis. At the same time, through vectorization and cluster analysis, the accuracy and efficiency of anomaly detection are improved, thereby effectively enhancing the security of the mobile application.
[0069] The method for detecting abnormal behavior of application program controls proposed according to the embodiments of the present application can extract interface and code semantic features from the application package, generate a complete program call graph, accurately lock the code context of the events triggered by the controls, and accordingly divide the subgraphs for implementing specific functions. Encode and vectorize the underlying instructions of the subgraphs, obtain the representation information in the vector space, and then combine the interface semantic features for clustering analysis to accurately detect the abnormal behavior of the application program controls, without relying on specific prior knowledge, adapting to various application scenarios, and effectively solving the problems of high false alarms, poor interpretability, and narrow applicability of traditional methods.
[0070] Next, a device for detecting abnormal behavior of application program controls proposed according to the embodiments of the present application will be described with reference to the accompanying drawings.
[0071] Figure 2 It is a block diagram of a device for detecting abnormal behavior of application program controls according to the embodiments of the present application.
[0072] As Figure 2 shown, the device 10 for detecting abnormal behavior of application program controls includes: an extraction module 100, a determination module 200, a division module 300, and a detection module 400.
[0073] Specifically, the extraction module 100 is configured to extract the interface semantic features and code semantic features in a preset application package, and generate a complete program call graph of the code in the application package based on the code semantic features.
[0074] The determination module 200 is configured to determine the code context of the events triggered by the application program controls according to the complete program call graph.
[0075] The division module 300 is configured to divide the complete program call graph based on the code context of the events triggered by the application program controls to generate a subgraph for implementing the specific functions of the events triggered by the application program controls.
[0076] The detection module 400 is configured to encode the underlying implementation instructions of each method included in the subgraph to obtain an encoded subgraph, vectorize the encoded subgraph to obtain the representation information of the behavior of the application program controls in the vector space, and perform clustering analysis based on the representation information to obtain the detection result of the abnormal behavior of the application program controls in combination with the interface semantic features.
[0077] Optionally, in an embodiment of the present application, the extraction module 100 includes: a first parsing unit, a second parsing unit, a third parsing unit, and an obtaining unit.
[0078] Among them, the first parsing unit is configured to parse the application interface list declared in the application manifest in the application package.
[0079] A second parsing unit, configured to parse a binary resource mapping list in an application package to obtain appearance attribute values corresponding to controls, and in the case where an appearance attribute value of an application control does not exist, supplement the missing appearance attribute value of the application control by using a preset static code.
[0080] A third parsing unit, configured to parse the inclusion relationships among the interface layout, control attributes, and sub-layouts defined in the layout file in the application package.
[0081] An obtaining unit, configured to obtain interface semantic features according to the application interface list, appearance attribute values, interface layout, control attributes, and inclusion relationships among sub-layouts.
[0082] Optionally, in an embodiment of the present application, the extraction module 100 includes: a decompilation unit and a control flow analysis unit.
[0083] Wherein, the decompilation unit is configured to perform code decompilation on the code in the application package to obtain the decompiled code.
[0084] The control flow analysis unit is configured to perform control flow analysis on the decompiled code to obtain code semantic features, and generate a complete program call graph according to the code semantic features.
[0085] Optionally, in an embodiment of the present application, the partitioning module 300 includes: a generating unit, an analyzing unit, and a trimming unit.
[0086] Wherein, the generating unit is configured to perform a callback starting from the trigger event of the application control, search for subsequent code contexts in the complete program call graph to generate multiple first subgraphs, and form a candidate set for the specific function implementation of the trigger event of the application control with the call codes of each method in the first subgraph.
[0087] The analyzing unit is configured to perform data flow analysis and code block analysis on the candidate set to exclude codes that are unreachable during actual operation in the candidate set.
[0088] The trimming unit is configured to trim the first subgraph based on the unreachable codes to obtain a subgraph for the specific function implementation of the trigger event of the application control.
[0089] Optionally, in an embodiment of the present application, the detection module 400 includes: a clustering analysis unit and an exception reporting unit.
[0090] Wherein, the clustering analysis unit is configured to detect the interface semantics of the application control and the subgraph for the specific function implementation of the trigger event by using clustering analysis, and mark the application control as abnormal in the case where the interface semantics are inconsistent with the subgraph for the specific function implementation of the trigger event.
[0091] An exception reporting unit is used to report to a security analyst the sub - graph that implements the specific functions of the event triggered by an application control marked as abnormal, so that the security analyst can troubleshoot and repair the application package.
[0092] It should be noted that the above - mentioned explanation of the embodiment of the method for detecting abnormal behavior of application controls also applies to the device for detecting abnormal behavior of application controls in this embodiment, and will not be elaborated here.
[0093] The device for detecting abnormal behavior of application controls proposed according to the embodiments of the present application can extract interface and code semantic features from an application package, generate a complete program call graph, accurately lock the code context of the event triggered by the control, and divide the sub - graph that implements specific functions accordingly. Encode and vectorize the underlying instructions of the sub - graph, obtain the characterization information of the vector space, and then combine the interface semantic features for clustering analysis to accurately detect the abnormal behavior of application controls. It does not rely on specific prior knowledge, adapts to a variety of application scenarios, and effectively solves problems such as high false alarms, poor interpretability, and narrow applicability of traditional methods.
[0094] Figure 3 The following is a schematic structural diagram of an electronic device provided by an embodiment of the present application. The electronic device may include:
[0095] A memory 301, a processor 302, and a computer program stored on the memory 301 and executable on the processor 302.
[0096] When the processor 302 executes the program, it implements the method for detecting abnormal behavior of application controls provided in the above - mentioned embodiment.
[0097] Furthermore, the electronic device further includes:
[0098] A communication interface 303 for communication between the memory 301 and the processor 302.
[0099] The memory 301 is used to store a computer program executable on the processor 302.
[0100] The memory 301 may include a high - speed RAM memory, and may also include non - volatile memory, such as at least one disk memory.
[0101] If the memory 301, the processor 302, and the communication interface 303 are implemented independently, the communication interface 303, the memory 301, and the processor 302 can be interconnected via a bus and communicate with each other. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 3 only a thick line is used in Figure 3 to represent it, but it does not mean that there is only one bus or one type of bus.
[0102] Optionally, in a specific implementation, if the memory 301, the processor 302, and the communication interface 303 are integrated on a single chip, the memory 301, the processor 302, and the communication interface 303 can communicate with each other through an internal interface.
[0103] The processor 302 may be a Central Processing Unit (CPU), or an Application Specific Integrated Circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application.
[0104] The embodiments of the present application further provide a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the method for detecting abnormal behavior of an application program control as described above is implemented.
[0105] The embodiments of the present application further provide a computer program product, where a computer-readable storage medium stores a computer program, and when the program is executed by a processor, the method for detecting abnormal behavior of an application program control as described above is implemented.
[0106] In the description of this specification, the descriptions referring to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of this application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any one or N embodiments or examples in a suitable manner. In addition, without contradiction, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.
[0107] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of such features. In the description of this application, the meaning of "N" is at least two, such as two, three, etc., unless otherwise specifically defined.
[0108] Any process or method description shown in a flowchart or described in other ways herein can be understood to represent a module, segment, or portion of code including one or N executable instructions for implementing a customized logic function or process, and the scope of the preferred embodiments of this application includes additional implementations, where the functions may be executed in a substantially simultaneous manner or in a reverse order according to the functions involved, rather than in the order shown or discussed, which should be understood by those skilled in the art to which the embodiments of this application belong.
[0109] The logic and / or steps represented in the flowchart or otherwise described herein can, for example, be considered a definitional sequence list of executable instructions for implementing logical functions, and can be embodied specifically in any computer-readable medium for use by or in connection with an instruction execution system, apparatus, or device, such as a computer-based system, a system including a processor, or other systems that can fetch and execute instructions from the instruction execution system, apparatus, or device. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of the computer-readable medium include the following: an electrical connection portion (electronic device) having one or N wirings, a portable computer diskette (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disc read-only memory (CDROM). Additionally, the computer-readable medium can even be paper or other suitable medium on which a program can be printed, as the program can be obtained electronically by optically scanning the paper or other medium, followed by editing, interpretation, or otherwise processing as appropriate, and then stored in a computer memory.
[0110] It should be understood that various parts of the present application can be implemented by hardware, software, firmware, or a combination thereof. In the above-described embodiments, the N steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. If implemented in hardware, as in another embodiment, any one or a combination of the following techniques known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), and the like.
[0111] Those of ordinary skill in the art of this technology can understand that all or part of the steps carried by the method of the above-described embodiments can be completed by a program instructing relevant hardware, and the program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiments.
[0112] In addition, each functional unit in various embodiments of the present application may be integrated into one processing module, or each unit may exist physically alone, or two or more units may be integrated into one module. The above integrated module may be implemented in the form of hardware or in the form of a software functional module. When the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium.
[0113] The above-mentioned storage medium may be a read-only memory, a magnetic disk or an optical disc, etc. Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present application. Those of ordinary skill in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of the present application.< / include>
Claims
1. A method for detecting abnormal behavior of application program controls, characterized in that, Including the following steps: Extract the interface semantic features and code semantic features in a preset application package, and generate a complete program call graph of the code in the application package based on the code semantic features; Determine the code context of the trigger event of the application control according to the complete program call graph; Divide the complete program call graph based on the code context of the trigger event of the application control to generate a sub-graph for the specific function implementation of the trigger event of the application control; Encode the underlying implementation instructions of each method included in the sub-graph to obtain an encoded sub-graph, vectorize the encoded sub-graph to obtain the representation information of the behavior of the application control in the vector space, and perform clustering analysis based on the representation information to combine with the interface semantic features to obtain the behavior anomaly detection result of the application control.
2. The method according to claim 1, wherein The extraction of the interface semantic features in the preset application package includes: Parse the application interface list declared in the application manifest in the application package; Parse the binary resource mapping list in the application package to obtain the appearance attribute values corresponding to the controls, and in the case where the appearance attribute values of the application controls do not exist, use preset static code to supplement the missing appearance attribute values of the application controls; Parse the interface layout defined in the layout file in the application package, the control attributes, and the inclusion relationship of the sub-layouts; Obtain the interface semantic features according to the application interface list, the appearance attribute values, the interface layout, the control attributes, and the inclusion relationship of the sub-layouts.
3. The method according to claim 1, characterized in that The extraction of the code semantic features in the preset application package and the generation of a complete program call graph of the code in the application package based on the code semantic features include: Perform code decompilation on the code in the application package to obtain the decompiled code; Perform control flow analysis on the decompiled code to obtain the code semantic features, and generate the complete program call graph according to the code semantic features.
4. The method according to claim 1, wherein The division of the complete program call graph based on the code context of the trigger event of the application control to generate a sub-graph for the specific function implementation of the trigger event of the application control includes: Perform a callback starting from the trigger event of the application control, search for the subsequent code context in the complete program call graph to generate multiple first sub-graphs, and form a candidate set for the specific function implementation of the trigger event of the application control by the call codes of each method in the first sub-graph; Perform data flow analysis and code block analysis on the candidate set to exclude the codes that are unreachable during actual operation in the candidate set; Based on the unreachable codes, trim the first sub-graph to obtain the sub-graph for the specific function implementation of the trigger event of the application control.
5. The method according to claim 1, wherein The clustering analysis based on the representation information to combine with the interface semantic features to obtain the behavior anomaly detection result of the application control includes: Use clustering analysis to detect the sub-graph of the interface semantics of the application program control and the specific function implementation of the trigger event. When the sub-graph of the interface semantics is inconsistent with the specific function implementation of the trigger event, mark the application program control as abnormal; Report the sub-graph of the specific function implementation of the trigger event of the application program control marked as abnormal to the security analyst so that the security analyst can check and repair the application program package.
6. An apparatus for detecting abnormal behavior of an application program control, characterized in that, Include: An extraction module for extracting the interface semantic features and code semantic features in a preset application program package, and generating a complete program call graph of the code in the application program package based on the code semantic features; A determination module for determining the code context of the trigger event of the application program control according to the complete program call graph; A division module for dividing the complete program call graph based on the code context of the trigger event of the application program control to generate a sub-graph of the specific function implementation of the trigger event of the application program control; A detection module for encoding the underlying implementation instructions of each method included in the sub-graph to obtain an encoded sub-graph, and vectorizing the encoded sub-graph to obtain the representation information of the behavior of the application program control in the vector space, and performing clustering analysis based on the representation information to obtain the behavior anomaly detection result of the application program control in combination with the interface semantic features.
7. The device according to claim 6, characterized in that, The extraction module includes: A first parsing unit for parsing the application interface list declared in the application manifest in the application program package; A second parsing unit for parsing the binary resource mapping list in the application program package to obtain the control and its corresponding appearance attribute values, and in the case where the application program control does not have the appearance attribute values, using preset static code to supplement the missing appearance attribute values of the application program control; A third parsing unit for parsing the interface layout defined in the layout file in the application program package, the control attributes and the inclusion relationship of the sub-layouts; An obtaining unit for obtaining the interface semantic features according to the application interface list, the appearance attribute values, the interface layout, the control attributes and the inclusion relationship of the sub-layouts.
8. An electronic device, characterized in that, Include: A memory, a processor, and a computer program stored on the memory and executable on the processor. The processor executes the program to implement the method for detecting the behavior anomaly of the application program control according to any one of claims 1-5.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, The program is executed by the processor to be used for implementing the method for detecting the behavior anomaly of the application program control according to any one of claims 1-5.
10. A computer program product, comprising a computer program, characterized in that, The computer program is executed to be used for implementing the method for detecting the behavior anomaly of the application program control according to any one of claims 1-5.
Citation Information
Cited By
Multi-source heterogeneous data intelligent analysis method and system
CN121786820A