Detection method and device

By running the application in a sandbox environment and obtaining memory topology and behavioral data, and performing multi-dimensional analysis with code characteristics, the accuracy of hot update package security detection is solved, and efficient identification of malicious behavior is achieved.

CN120371368APending Publication Date: 2025-07-25VIVO MOBILE COMM CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510455283.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-11
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

In the prior art, the security detection of hot update packages has low accuracy in detecting new and unknown malicious codes, and is prone to missed and missed detection.

Method used

By running the application in a sandbox environment and installing the hot update package, we obtain topological information of the memory space and the application's behavior data, and conduct multi-dimensional analysis based on code characteristics, including static and dynamic analysis, to detect the security of the hot update package of the application.

Benefits of technology

It improves the accuracy of safety detection of hot update packages, reduces the missed detection rate and false detection rate, and can effectively detect dynamic and hidden malicious behavior.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120371368A_ABST
    Figure CN120371368A_ABST
Patent Text Reader

Abstract

The invention discloses a detection method and device. Belongs to the technical field of computers. The method comprises the steps that under the condition that an application hot update package of an application is received, code features of the application hot update package are obtained; running an application in the sandbox environment and installing an application hot update package, and obtaining topological information of a memory space and first behavior data of the application; and determining whether the application hot update package is safe or not based on the code features, the topological information and the first behavior data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of computer technology, and particularly to a detection method and device. Background Art

[0002] Hot update is a technology used for mobile applications or software development. It allows developers to dynamically distribute code or resource files through the cloud after the application is released, so as to update the code logic or resources of the application without the need to re-download and install the entire application on the terminal device. The main purpose of the hot update technology is to quickly fix vulnerabilities, update functions or optimize performance, while reducing user waiting and operations. However, malicious developers can use hot updates to inject malicious code, so it is necessary to perform security detection on application hot update packages.

[0003] In the prior art, it is usually determined whether an application hot update package is secure by scanning the code and resource files of the application hot update package to find known malicious code features, security vulnerabilities or content that does not conform to security specifications. This method is prone to missed detections and false detections for new and unknown attack methods or variant malicious codes. Therefore, the accuracy of security detection for application hot update packages is relatively low. Summary of the Invention

[0004] The purpose of the embodiments of the present application is to provide a detection method and device, which improve the accuracy of security detection for application hot update packages.

[0005] In a first aspect, the embodiments of the present application provide a detection method, which includes: when receiving an application hot update package of an application, obtaining the code features of the application hot update package; running the application in a sandbox environment and installing the application hot update package, obtaining the topological information of the memory space and the first behavior data of the application; and determining whether the application hot update package is secure based on the code features, the topological information and the first behavior data.

[0006] In a second aspect, the embodiments of the present application provide a detection device, which includes: a first acquisition unit, configured to obtain the code features of the application hot update package when receiving the application hot update package of the application; a second acquisition unit, configured to run the application in a sandbox environment and install the application hot update package, and obtain the topological information of the memory space and the first behavior data of the application; and a determination unit, configured to determine whether the application hot update package is secure based on the code features, the topological information and the first behavior data.

[0007] In a third aspect, the embodiments of the present application provide an electronic device, which includes a processor and a memory. The memory stores a program or instruction that can run on the processor, and when the program or instruction is executed by the processor, the steps of the method described in the first aspect are implemented.

[0008] Fourthly, an embodiment of the present application provides a readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method described in the first aspect above are implemented.

[0009] Fifthly, an embodiment of the present application provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the method described in the first aspect.

[0010] Sixthly, an embodiment of the present application provides a computer program product, which is stored in a storage medium and is executed by at least one processor to implement the method described in the first aspect.

[0011] In the embodiment of the present application, firstly, when an application hot update package of an application is received, the code features of the application hot update package are obtained; then the application is run in a sandbox environment and the application hot update package is installed, and the topology information of the memory space and the first behavior data of the application are obtained; finally, based on the code features, topology information and first behavior data, it is determined whether the application hot update package is safe. Among them, through the detection of code features, the static analysis of the application hot update package is realized; after running the application in the sandbox and installing the application hot update package, by detecting the topology information of the memory space and the first behavior data of the application, the memory and the behavior of the application can be monitored in real time, so as to effectively discover dynamic and hidden malicious behaviors, and the dynamic analysis of the application hot update package is realized. By combining static analysis and dynamic analysis, the multi-dimensional analysis and comprehensive security detection of the application hot update package are realized, the missed detection rate and false detection rate of the security detection of the application hot update package are reduced, and the accuracy of the security detection of the application hot update package is improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] Figure 1 is a flowchart of the detection method provided by the embodiment of the present application;

[0013] Figure 2 is a schematic structural diagram of the detection device provided by the embodiment of the present application;

[0014] Figure 3 is a schematic structural diagram of the electronic device provided by the embodiment of the present application;

[0015] Figure 4 is a schematic hardware structure diagram of the electronic device suitable for implementing the embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0016] Next, the technical solutions in the embodiments of the present application will be clearly described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art belong to the scope of protection of the present application.

[0017] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second", etc. are usually of the same category, and the number of objects is not limited. For example, the first object can be one or multiple. In addition, "and / or" in the specification and claims means at least one of the connected objects, and the character " / " generally indicates an "or" relationship between the related objects before and after.

[0018] Next, in conjunction with the accompanying drawings, the detection methods and devices provided in the embodiments of the present application will be described in detail through specific embodiments and their application scenarios.

[0019] Please refer to Figure 1 , which shows one of the flowcharts of the detection method provided in the embodiments of the present application. The detection method provided in the embodiments of the present application can be applied to an electronic device. In practice, the above-mentioned electronic device can be an electronic device such as a smart phone, a tablet computer, a laptop computer, a wearable device, etc.

[0020] The flow of the detection method provided in the embodiments of the present application includes the following steps:

[0021] Step 101, when receiving an application hot update package of an application, obtain the code features of the application hot update package.

[0022] In this embodiment, an application hot update package refers to a data packet that realizes software update by downloading and replacing part of the resources or code through hot update technology during the operation of the application. The application hot update package may include, but is not limited to, content such as resource data and code. The electronic device does not need to re-download and install the complete software installation package, but only needs to download and update the part of the resources or code, and then replace the old resources in the application, so as to realize the instant update of the application.

[0023] Specifically, after detecting a hot update request of the application, the application hot update package sent by the server can be intercepted. The above-mentioned hot update request can be actively triggered by the user, can be triggered by the application regularly, or can be triggered after receiving a remote instruction, which is not specifically limited here.

[0024] Next, resources such as code, dependency libraries, and metadata can be extracted from the application hot update package. It can be understood that a unique identifier can also be created to indicate the application hot update package. Based on this identifier, the timestamp, source IP (Internet Protocol) address, digital signature, etc. of the application hot update package can be determined.

[0025] Next, the code features of the application hot update package can be extracted from the above resources. The code features can be extracted by various feature extraction methods. For example, they can be extracted by a pre-trained neural network, which is not specifically limited here.

[0026] Step 102, run the application in a sandbox environment and install the application hot update package to obtain the topological information of the memory space and the first behavior data of the application.

[0027] In this embodiment, a sandbox is a security mechanism used to run programs or execute code in an isolated environment to prevent potential malware or untrusted code from damaging the system or accessing sensitive data. In practice, virtualization technology or containerization technology, such as Docker or KVM (Kernel-based Virtual Machine), etc., can be used to pre-build an isolated sandbox environment to ensure that when the application runs in the sandbox environment, it is isolated from the host system and other applications, preventing the application hot update package from posing potential security threats to the system. The sandbox environment should have an operating system, runtime libraries, and dependent components similar to the actual running environment to ensure that the behavior of the application in the sandbox environment is as consistent as possible with that in the real environment.

[0028] In this embodiment, the application and the application hot update package can be deployed to the sandbox environment, that is, run the application in the sandbox environment and install the application hot update package. The installation process should simulate the real user installation scenario, including operations such as decompressing the installation package, configuring runtime parameters, and initializing application data, to ensure that the application can be normally started and run in the sandbox environment.

[0029] Next, obtain the topology information of the memory space. In practice, a memory monitoring tool can be used to obtain the topology information of the memory space. The memory monitoring tool can intercept and record operations such as memory allocation, release, reading, and writing at the operating system level, and obtain detailed data associated with memory access. Exemplarily, a memory monitoring tool can be used to record the allocation of heap memory, such as the size, starting address, and allocation time of each memory allocation; record the timing changes of stack frames, such as the size, starting address, and function call relationship of each stack frame; record the call data of the target interface, such as parameter passing and return values of JNI (Java Native Interface) bridge calls. The above JNI interface can be used for the interaction between Java code and code in other languages. One or more of the above information can be subjected to operations such as format conversion and summarization to obtain the topology information.

[0030] Meanwhile, during the running of the application, various behavior data generated by the application can be obtained as the first behavior data. The first behavior data can be used to indicate the running state and behavior characteristics of the application after installing the application hot update package, and is an important basis for subsequent security detection. The first behavior data can include, but is not limited to, at least one of the following: function call records, interface call records, file read and write records, memory allocation and release situations, network communication records, etc.

[0031] It can be understood that after running the application in the sandbox environment and installing the application hot update package, the operations of the user in the application can be further simulated. For example, if the historical operation information shows that the user has performed operations such as logging in and sending messages, then these operations are executed in the sandbox environment in the same order and with the same parameters. Among the above first behavior data, the behavior data generated by the application in response to the above operations can be included.

[0032] Step 103, based on the code features, topology information, and the first behavior data, detect whether the application hot update package is secure.

[0033] In this embodiment, the similarity between the code features and the code features of the historical secure hot update package of the above application can be calculated to obtain the similarity calculation result. When the similarity calculation result is less than the similarity threshold, it can be considered that there may be malicious code in the current application hot update package. On the contrary, further detection can be performed based on the topology information of the memory space.

[0034] Based on the topological information of the memory space, it is possible to detect whether there are abnormal behaviors in the application during runtime after the installation of the application hot update package, such as heap spraying attacks, abnormal stack frame inflation, covert dependency injection, etc. Among them, a heap spraying attack is an attack method that uses program vulnerabilities to write a large amount of malicious data into the heap memory. The attacker tries to arrange executable malicious code in the heap by controlling the allocation and release of the heap memory to achieve illegal operations. Abnormal stack frame inflation refers to the phenomenon that during the program's runtime, the size of the stack frame exceeds the normal range, which may lead to stack overflow or abnormal program behavior. Covert dependency injection is an attack method that injects malicious code or dependency relationships into the application through covert means. The attacker dynamically changes the program's execution flow by tampering with function pointers, virtual tables, etc., causing the program to execute unexpected code during runtime. Exemplarily, if a large number of continuously similar-structured memory allocations are determined based on the topological information of the memory space, it can be judged that there is a heap spraying attack behavior; if it is determined based on the topological information of the memory space that the size of the stack frame exceeds the normal range due to excessive function call depth, it can be judged that there is abnormal stack frame inflation; if it is determined based on the topological information of the memory space that there is an abnormality in the pointer trajectory of a certain interface call, it can be judged that the application has suffered from covert dependency injection.

[0035] Based on the first-line data, it is possible to further detect whether there are abnormal behaviors in the application when the user performs operations in the application after the installation of the application hot update package, such as sensitive operation chains, abnormal control flows, resource competition behaviors, etc. A sensitive operation chain refers to a sequence of function calls or interface calls involving sensitive operations. If these operations are maliciously exploited, it may lead to serious consequences such as user data leakage and system intrusion. An abnormal control flow refers to the situation where the program's execution flow deviates from the normal logic, such as unexpected loops, abnormal recursion depths, jumps to illegal addresses, etc., which may be caused by malicious code tampering or serious vulnerabilities in the program. A resource competition behavior refers to the phenomenon that multiple threads or processes access shared resources simultaneously without a proper synchronization mechanism, resulting in inconsistent resource states or abnormal program behaviors, which may cause problems such as data loss and program crashes. Exemplarily, when it is detected that the application frequently performs file read and write operations after the user logs in and the file paths are abnormal, it may imply malicious behavior. If abnormal behaviors are detected, it can be considered that there may be malicious code in the current application hot update package. Conversely, it can be determined that the application hot update package is safe, or more information can be combined for further detection and the application hot update package can be determined to be safe after passing the detection.

[0036] It should be noted that the methods and detection orders for detecting the security of the application hot update package based on code features, topological information, and first-line data are not limited to the above descriptions. For example, it is also possible to perform the security detection of the application hot update package based on the above information simultaneously, and determine whether the application hot update package is safe by synthesizing the detection results of each item.

[0037] Optionally, it is also possible to further perform risk assessment and further decision-making on the applied hot update package. The risk level can be divided into high risk, medium risk, and low risk. If situations such as memory tampering or sandbox escape are detected, the applied hot update package can be rated as high risk. At this time, the update can be blocked, an alarm message can be generated, and the affected process can be isolated to prevent the spread of risks. Among them, sandbox escape refers to the situation where the functional modules in the applied hot update package attempt to break through the limitations of the sandbox and affect other modules of the application. If some unauthorized interface call behaviors are detected but no actual harm has been caused, the applied hot update package can be rated as medium risk. The permissions of the corresponding module can be restricted, and the administrator can be notified for manual review to further confirm whether there are risks. If no abnormalities are detected, the applied hot update package can be rated as low risk or safe. At this time, the update can be released, and at the same time, the fingerprint features of the applied hot update package, the behavior data of the application, etc. can be recorded for subsequent traceability and analysis when needed.

[0038] The method provided by the above embodiments of this application first, when receiving the applied hot update package of an application, obtains the code features of the applied hot update package; then runs the application in a sandbox environment and installs the applied hot update package, and obtains the topological information of the memory space and the first behavior data of the application; finally, based on the code features, topological information, and first behavior data, it detects whether the applied hot update package is safe. Among them, through the detection of the code features, the static analysis of the applied hot update package is realized; after running the application in the sandbox and installing the applied hot update package, by detecting the topological information of the memory space and the first behavior data of the application, it is possible to monitor the memory and the behavior of the application in real time, so as to effectively discover dynamic and hidden malicious behaviors, and realize the dynamic analysis of the applied hot update package. By combining static analysis and dynamic analysis, the multi-dimensional analysis and comprehensive security detection of the applied hot update package are realized, reducing the missed detection rate and false detection rate of the security detection of the applied hot update package, and improving the accuracy of the security detection of the applied hot update package.

[0039] In some optional embodiments, in the above step 101, the code features of the applied hot update package can be obtained through the following steps:

[0040] Step S11, convert the code of the applied hot update package into an abstract syntax tree.

[0041] Specifically, a professional code deconstruction tool, such as ANTLR or Roslyn, etc., can be used to convert the code of the applied hot update package into an abstract syntax tree (Abstract Syntax Tree, AST). The abstract syntax tree is a tree-like data structure, and each node in it represents a syntax construct in the code, such as function definitions, statement blocks, expressions, etc.

[0042] Exemplarily, assume that the application hot update package contains a function, which is converted into an abstract syntax tree by a code deconstruction tool. The root node of the tree can represent the function definition, and the child nodes represent each statement and expression within the function body, specifically including but not limited to the return type, function name, parameter list, and function body, etc.

[0043] Step S12, extract the structured information from the abstract syntax tree.

[0044] Specifically, the structured information includes at least one of the following: topological information of the Control Flow Graph (CFG), data dependency relationship information, depth information of the function call tree, etc. Each of the above structured information can be represented by a graph structure.

[0045] The control flow graph is a directed graph depicting the program execution flow. Its nodes represent basic blocks, where a basic block is a continuous sequence of instructions that are executed sequentially without branches. The edges represent the transfer of control flow, that is, the jump from one basic block to another. For example, in a function with conditional judgments and loops, the control flow graph can clearly show the execution paths of different conditional branches and the entry and exit of loops. The topological information of the control flow graph can be used to indicate the organization method of nodes and edges in the control flow graph, including the connection relationship between nodes and the hierarchical structure of nodes. It reflects the complexity and logical structure of the program execution flow.

[0046] The data dependency relationship information is used to record the data flow relationship between variables. The data dependency relationship information can specifically include the weight distribution of data dependency edges. Among them, the data dependency edge represents the data flow relationship between variables. In a program, the value of a variable may depend on the value of other variables, and this dependency relationship can be represented by a data dependency edge. The weight distribution reflects the importance or occurrence frequency of the data dependency edge in the program. The weight of the data dependency edge can be determined based on various factors, such as the frequency of variable access and the scope of variable use in the program. The weight distribution shows the distribution of different data dependency edges in the program, which helps to understand the data flow pattern and critical path in the program.

[0047] The depth information of the function call tree reflects the hierarchical structure and depth of function calls, which is of great significance for understanding the modularity and call relationships of software systems. Among them, the function call tree is a tree structure used to represent function call relationships. In the function call tree, the root node represents the main function, and other nodes represent the called functions. The depth feature of the function call tree refers to the length of the longest path from the root node to the leaf node, that is, the nesting level of function calls. The depth of the function call tree reflects the complexity of function calls. A function call tree with a deeper depth may indicate that the program has a complex modular structure or recursive calls, etc.

[0048] Step S13, convert the structured information through a graph embedding algorithm to obtain code features.

[0049] The graph embedding algorithm can be used to convert graph-structured data into a vector representation algorithm, which has a wide range of applications in the fields of machine learning and data mining. It can map the structural information of the graph into a vector space for subsequent analysis and processing. The graph embedding algorithm can include, but is not limited to, algorithms such as Graph2Vec and Node2Vec. Through the graph embedding algorithm, the extracted structured information is converted into high-dimensional vectors to obtain code features.

[0050] By converting the code of the applied hot update package into an abstract syntax tree and extracting structured information, the semantic features of the code can be captured more accurately. The structured information is converted into high-dimensional vectors through the graph embedding algorithm to generate code features, which is convenient for subsequent similarity calculation and anomaly detection.

[0051] In some alternative embodiments, in the above step 102, the topological information of the memory space can be obtained through the following steps, including:

[0052] Step S21, adopt the page table mapping redirection technology to obtain memory access data.

[0053] In the operating system, the memory is divided into fixed-size pages (usually 4KB or 2MB, etc.). Each page has a corresponding page frame in physical memory. The page table is a data structure used to map virtual addresses to physical page frames. The page table entry (PTE) contains the mapping relationship between virtual pages and physical page frames. The page table mapping redirection technology is a low-level technology used in operating system memory management, mainly used to manage and control the access of processes to physical memory. The page table mapping redirection technology can modify the page table entries to redirect virtual addresses to different physical memory pages, thereby achieving fine-grained control of memory access. When performing memory monitoring or analysis, certain virtual pages of the target process can be redirected to the physical page frames controlled by the monitoring agent, thereby triggering specific processing logic when accessing these pages.

[0054] The memory access data includes at least one of the following: allocation data of the heap memory, timing change data of the stack frames, and call data of the target interface. Among them, the heap memory is a memory area dynamically allocated during program operation, used to store object instances, dynamic data structures, etc. The allocation data of the heap memory can indicate the allocation situation of the heap memory, and specifically can include information such as the size, starting address, and allocation time of the heap memory dynamically allocated during the operation of the application. A stack frame is the space allocated in memory during a function call, used to store local variables, parameters, return addresses, etc. during the function call. The timing change data of the stack frames can be used to indicate the creation, destruction, and changes of the stack frames during the function call process. The target interface can include, but is not limited to, JNI. The call data of the target interface can indicate the call situation of the target interface in the application, and can include, but is not limited to, the pointer trace of the JNI bridge call.

[0055] Step S22: Generate topological information of the memory space based on the memory access data.

[0056] Specifically, memory monitoring tools such as Valgrind, Intel PIN, etc. can be used to analyze and process the memory access data to generate topological information of the memory space, such as a three-dimensional topological map of the memory space, etc.

[0057] Based on the allocation data of the heap memory, information such as the size, starting address, and allocation time of each memory block can be determined. By analyzing this information, an allocation matrix of the heap memory can be constructed to show the usage pattern of the heap memory. The rows of the allocation matrix of the heap memory can represent different heap memory allocation events; the columns can represent key information such as the size and address of the heap memory allocation.

[0058] Based on the timing change data of the stack frames, the creation and destruction of the stack frames during the process operation can be tracked, and the size, starting address, function call relationship, etc. of each stack frame can be recorded. By analyzing the timing changes of the stack frames, the depth, frequency of function calls, and the structure of the call chain can be understood, and the timing change information of the stack frame structure can be generated.

[0059] Based on the call data of the target interface, for the process involving JNI calls, the changes in pointers during the JNI bridge call process can be monitored, including parameter passing, return values, etc. By recording these pointer traces, the complete path and data flow of the JNI call can be analyzed, and a pointer trace map of the JNI call can be generated.

[0060] By using the page table mapping redirection technology to obtain the memory access data and generate the topological information of the memory space, the memory usage of the application hot update package during operation can be comprehensively understood. This method can effectively detect hidden malicious behaviors such as heap spraying attacks, abnormal stack frame inflation, and hidden dependency injection, improving the depth and breadth of detection.

[0061] In some alternative embodiments, in step 102 above, obtaining the first behavior data of the application hot update package may be performed according to the following steps:

[0062] Step S31, obtain the historical operation information of the user in the application.

[0063] Specifically, the historical operation information of the user in the application can be extracted from the log file of the application. For example, it may include but is not limited to operations such as user login, sending messages, page browsing, updating personal profiles, etc.

[0064] Step S32, perform operations on the application in the sandbox environment based on the historical operation information, and obtain the first behavior data generated by the application in response to the operations.

[0065] Specifically, in the sandbox environment, according to the obtained historical operation information, user operations can be simulated. For example, if the historical operation information shows that the user has performed operations such as login and sending messages, then these operations are performed in the sandbox environment in the same order and with the same parameters. In practice, automation tools or scripts can be used to automatically perform corresponding operations according to the operation sequence in the historical operation information. During the process of performing the operations, the real-time behavior data of the application is collected to obtain the first behavior data. The first behavior data may include but is not limited to function call records, interface call records, file read and write records, memory allocation and release situations, network communication records, etc.

[0066] It can be understood that it is also possible to only obtain the behavior data generated by the update module of the application in response to the above operations to obtain the first behavior data. Among them, the update module can be a functional module in the application hot update package.

[0067] Exemplarily, a social application can be run in the sandbox environment. According to the historical operation information of the user, operations such as user login, sending messages, and updating personal profiles are simulated, and the behavior data of the update module of the application under these operations, such as the functions called, interfaces accessed, memory size allocated, network requests sent, files operated on, etc., are recorded to obtain the first behavior data.

[0068] By obtaining the historical operation information of the user in the application and performing operations on the application in the sandbox environment based on the history, the dynamic behavior of the update module in the actual usage scenario can be comprehensively understood. This method can effectively detect abnormal behaviors of the update module under user operations, such as sensitive operation chains, abnormal control flows, resource competition behaviors, etc., and improve the practicality and pertinence of detection.

[0069] In some alternative embodiments, in step 103 above, based on the code features, topology information, and the first behavior data, determining whether the application hot update package is secure may be performed according to the following steps:

[0070] Step S41: Calculate the similarity between the code features and the code features of the historical secure hotfix package to obtain the similarity calculation result.

[0071] The historical secure hotfix package can be an installation package that has been detected as secure in the historical update packages of the application. Similarity calculation methods such as the cosine similarity algorithm and Euclidean distance can be used to calculate the similarity between the code features and the code features of the historical secure hotfix package to obtain the similarity calculation result. In practice, a similarity threshold can be set. When the similarity calculation result is less than the threshold, it can be considered that there may be malicious code in the current application hotfix package.

[0072] Step S42: Based on the topological information, detect whether there are abnormal behaviors during the operation of the application after the installation of the application hotfix package to obtain the first detection result.

[0073] Based on the topological information of the memory space, it can be detected whether there are abnormal behaviors such as heap spraying attacks, stack frame abnormal inflation, and covert dependency injection during the operation of the application after the installation of the application hotfix package.

[0074] Optionally, the topological information of the memory space includes the allocation matrix of the heap memory. Based on the allocation matrix of the heap memory, a data analysis algorithm can be used to detect whether there is a memory allocation pattern with a large number of consecutive similar structures. For example, check whether there are multiple heap blocks with the same or similar sizes and similar content patterns. If it is determined that there is a memory allocation model with a large number of consecutive similar structures, it means that there may be a heap spraying attack. A heap spraying attack is an attack method that uses program vulnerabilities to write a large amount of malicious data into the heap memory. The attacker controls the allocation and release of the heap memory and arranges executable malicious code in the heap to achieve illegal operations. Usually, a heap spraying attack will allocate a large number of heap blocks with a specific pattern, and the sizes and contents of these heap blocks are similar.

[0075] Optionally, the topological information of the memory space includes stack frame timing change data. Based on the timing change information of the stack frame structure, the change in the function call depth can be determined through a timing analysis algorithm. The function call depth reflects the nested level of function calls. Under normal circumstances, the change in the function call depth is gentle and regular. However, when there is abnormal inflation of the stack frame in the program, the function call depth may increase abnormally. In addition, a reasonable threshold can be set according to the function call depth distribution during normal program operation. This threshold can be obtained based on historical data statistics. During the program operation, the current function call depth can be compared with the set threshold in real time. If the current function call depth exceeds the threshold, it indicates that there may be abnormal inflation of the stack frame. Abnormal inflation of the stack frame refers to the phenomenon that the size of the stack frame exceeds the normal range during program operation, which may lead to stack overflow or abnormal program behavior. Abnormal inflation of the stack frame is usually caused by security vulnerabilities such as buffer overflow and stack overflow. When a buffer in the program is written with data exceeding its capacity, it will cause the size of the stack frame to exceed the normal range, which may damage the data in other stack frames and even overwrite the return address, thus executing arbitrary code.

[0076] Optionally, the topological information of the memory space includes the pointer trace of JNI bridge calls. Based on the pointer trace of JNI bridge calls, information such as parameter passing, return values, call frequencies, etc. of JNI bridge calls, as well as changes in key pointers such as function pointers and virtual table pointers, can be obtained. Data analysis algorithms can be used to determine whether there are abnormalities in this pointer trace. For example, check whether the function pointer is abnormally modified or the virtual table pointer is tampered with. If there are abnormalities, it means that the application has suffered from covert dependency injection. Covert dependency injection is an attack method that injects malicious code or dependency relationships into the application through covert means such as function pointer hijacking and virtual table tampering. Attackers dynamically change the execution flow of the program by tampering with function pointers, virtual tables, etc., causing the program to execute unexpected code during operation.

[0077] Step S43: Based on the first-line data, detect whether there are abnormal behaviors in the application when the application hot update package is installed and the user performs operations in the application, and obtain the second detection result.

[0078] Based on the first-line data, it is possible to further detect whether there are abnormal behaviors in the application when the user performs operations in the application after the application hot update package is installed, such as sensitive operation chains, abnormal control flows, resource competition behaviors, etc.

[0079] Optionally, sensitive operation chains can be detected based on the first-line behavior data. Specifically, records of file reading and writing, network communication, permission applications, etc. in the first-line behavior data can be extracted to obtain information such as the type, time, and parameters of each operation. Then, based on the extracted records, operation chains can be constructed to analyze the order and association between operations. Subsequently, the constructed operation chains can be matched with preset sensitive operation chains to determine whether the constructed operation chains are sensitive operation chains. Among them, the preset sensitive operation chains can be set according to security policies and experience. Exemplarily, the preset sensitive operation chains can include, but are not limited to, "file reading - network sending", "permission application - file writing", etc. If the constructed operation chain includes "file reading - network sending", it may involve user data leakage; if the constructed operation chain includes "permission application - file writing", it may involve malicious writing of user data.

[0080] Optionally, unexpected loops, recursive depth mutations, etc. can be determined based on the first-line behavior data, thereby determining the existence of abnormal control flow. Specifically, the function call sequence and loop information can be first extracted from the first-line behavior data, and the depth of each function call, the number of loop iterations, etc. can be recorded. Then, the changing trends of the function call depth and the number of loop iterations can be analyzed to determine whether there are abnormalities. Among them, reasonable thresholds can be set in advance according to the control flow pattern during normal program operation, such as function call depth thresholds, loop iteration number thresholds, etc. During the application running process, the current control flow information is compared with the set thresholds in real time, and if the threshold is exceeded, it can be determined that there is abnormal control flow.

[0081] Optionally, behaviors such as thread deadlocks, CPU (Central Processing Unit) / memory occupancy magnitude deviating from the baseline, etc. can be determined based on the first-line behavior data, and resource competition behaviors can be determined according to this behavior. Specifically, the resource usage information such as thread status, CPU usage rate, and memory usage rate can be first extracted from the first-line behavior data. Then, based on the above-mentioned extracted information, the changing trends of the thread status change, CPU, and memory usage rates are analyzed to determine whether there are abnormalities. Among them, the baseline and reasonable thresholds can be set in advance according to the resource usage situation during normal program operation, such as thread waiting time threshold, CPU usage rate threshold, memory usage rate threshold, etc. During the application running process, the current resource usage information is compared with the set baseline and thresholds in real time, and if the threshold is exceeded, it is determined that there is a resource competition behavior.

[0082] Step S44, based on the similarity calculation result, the first detection result, the second detection result, and the third detection result, determine whether the application hot update package is safe.

[0083] Specifically, the above various detection results can be comprehensively analyzed, and a machine learning model or a rule engine can be used to finally determine whether the application hot update package is safe according to the preset weights and decision logics. Exemplarily, if the similarity calculation result is higher than the threshold, no abnormality is found in the memory detection, and no abnormality is found in the behavior detection, it can be comprehensively determined that the application hot update package is safe.

[0084] By comprehensively considering the similarity calculation result, the first detection result, and the second detection result, multi-dimensional security detection is achieved, which can effectively identify malicious code, runtime abnormal behaviors, and abnormal changes in functional modules in the application hot update package, significantly improving the accuracy and reliability of detection and enhancing the ability of the application system to resist potential security risks of hot updates.

[0085] In some optional embodiments, after the above step S43 is executed, the following steps can also be executed:

[0086] Step S44: For the functional modules in the application hot update package, based on the first behavior data and the historical behavior data of the application after installing the historical secure hot update package, determine whether the functional modules are abnormal to obtain a third detection result.

[0087] Specifically, the historical behavior data of the application after installing the historical secure hot update package can be obtained first; then, for the functional modules in the application hot update package, the first behavior data can be compared with the historical behavior data, and methods such as time series analysis, path matching, and dependency graph analysis can be used to detect whether the update time sequence, behavior path, and dependency relationship with other modules in the application of the functional module are abnormal to obtain a third detection result.

[0088] Among them, an abnormal update time sequence refers to a situation where the update time, update frequency, etc. of the functional module do not conform to the normal business logic or historical update pattern, which may be a sign of an attacker gradually injecting malicious code. An abnormal behavior path means that the execution path of the functional module after the update is significantly different from the normal situation, which may indicate that the functional logic has been maliciously tampered with or a malicious function has been added. An abnormal dependency relationship means that the dependency relationship between the functional module and other modules or libraries has changed unexpectedly, which may be the result of covert dependency injection or malicious modification of the function.

[0089] Exemplarily, after comparing the first behavior data and the historical behavior data, if it is detected that the call frequency of the functional module increases significantly after the update, it may imply an abnormal update time sequence; if it is detected that the behavior path is significantly different from the historical data, it may imply an abnormal behavior path; if it is detected that the dependency relationship between the functional module and other modules in the application has changed, it may imply an abnormal dependency relationship.

[0090] By comparing the first-line data with the historical behavior data, the behavioral changes of the functional module after the update can be comprehensively understood. This method can effectively discover the abnormal update timing, behavioral paths, and dependencies of the functional module, improve the depth and breadth of detection, and enhance the ability of the application system to resist potential security risks of hot updates.

[0091] Further, in the above step S44, based on the similarity calculation result, the first detection result, the second detection result, and the third detection result, it can be determined whether the above application hot update package is safe. Specifically, the above various detection results can be comprehensively analyzed, using a machine learning model or a rule engine, and according to the preset weights and decision logics, finally determine whether the application hot update package is safe. Exemplarily, if the similarity calculation result is higher than the threshold, no abnormality is found in the memory detection, no abnormality is found in the behavior detection, and no abnormality is found in the functional module detection, it can be comprehensively judged that the application hot update package is safe.

[0092] By comprehensively using means such as similarity calculation, memory abnormal behavior detection, behavior abnormal detection, and functional module abnormal detection, an all-round and multi-dimensional security detection of the application hot update package is realized. It can effectively overcome the problems of missed reports, false reports, and the inability to detect complex malicious behaviors existing in the single detection method in the prior art, significantly improve the detection accuracy and reliability, and enhance the ability of the application system to resist potential security risks of hot updates.

[0093] In some alternative embodiments, after the above step 103 is executed, the following steps can also be executed:

[0094] Step S51, install the application hot update package when it is detected that the application hot update package is safe.

[0095] After completing the multi-dimensional security detection of the application hot update package, if its security is confirmed, the application hot update package can be installed in the application, which usually involves copying the updated code and resource files to the specified directory of the application and performing necessary configuration updates.

[0096] Step S52, during the operation of the application, obtain the second behavior data of the application.

[0097] During the operation of the application, the behavior data of the application can be continuously obtained, denoted as the second behavior data. The second behavior data may include but is not limited to at least one of the following: function call records, interface call records, file read and write records, memory allocation and release situations, network communication records, etc.

[0098] Step S53, based on the second behavior data, update the security detection rules for the application hot update package of the application.

[0099] Specifically, the second-line behavior data collected can be analyzed to identify new behavior patterns and potential security threats. Then, based on the analysis results, the security detection rules can be updated. For example, new feature fingerprints can be added, the weights of risk assessment can be adjusted, etc. Further, the updated rules can be verified to ensure that they can accurately detect new security threats while avoiding false positives.

[0100] By continuously monitoring the behavior data during the operation of the application and dynamically optimizing the security detection rules according to the new data, continuous improvement of the security detection of the application hot update package is achieved. This method can effectively cope with the ever-changing security threats, improve the adaptability and accuracy of detection, and enhance the ability of the application system to resist potential security risks of hot updates.

[0101] It should be noted that for the detection method provided in the embodiments of the present application, the execution subject can be a detection device. In the embodiments of the present application, taking the detection device executing the detection method as an example, the detection device provided in the embodiments of the present application is described.

[0102] As Figure 2 shown, the detection device 200 in this embodiment includes: a first acquisition unit 201, configured to acquire the code features of the application hot update package of the application when receiving the application hot update package; a second acquisition unit 202, configured to run the application in a sandbox environment and install the application hot update package, and acquire the topological information of the memory space and the first behavior data of the application; a determination unit 203, configured to determine whether the application hot update package is secure based on the code features, the topological information, and the first behavior data.

[0103] In some optional implementation manners of this embodiment, the first acquisition unit 201 is further configured to: convert the code of the application hot update package into an abstract syntax tree; extract structured information from the abstract syntax tree, where the structured information includes at least one of the following: control flow graph, data dependency information, depth information of the function call tree; perform conversion processing on the structured information through a graph embedding algorithm to obtain code features. By converting the code of the application hot update package into an abstract syntax tree and extracting structured information, the semantic features of the code can be captured more accurately. By converting the structured information into a high-dimensional vector through a graph embedding algorithm to generate code features, it is convenient for subsequent similarity calculation and anomaly detection.

[0104] In some alternative implementation manners of this embodiment, the second acquisition unit 202 is further configured to: obtain memory access data by using a page table mapping redirection technique, where the memory access data includes at least one of the following: allocation data of heap memory, stack frame timing change data, and call data of a target interface; generate topology information of a memory space based on the memory access data. By obtaining memory access data by using a page table mapping redirection technique and generating topology information of a memory space, the memory usage of the application hot update package during runtime can be comprehensively understood. This method can effectively detect hidden malicious behaviors, such as heap spraying attacks, abnormal stack frame inflation, and covert dependency injection, improving the depth and breadth of detection.

[0105] In some alternative implementation manners of this embodiment, the second acquisition unit 202 is further configured to: obtain historical operation information of a user in the application; perform an operation on the application in a sandbox environment based on the historical operation information, and obtain first behavior data generated by the application in response to the operation. By obtaining historical operation information of a user in the application and performing an operation on the application in a sandbox environment based on the historical operation, the dynamic behaviors of the update module in an actual usage scenario can be comprehensively understood. This method can effectively detect abnormal behaviors of the update module under user operations, such as sensitive operation chains, abnormal control flows, and resource competition behaviors, improving the practicality and pertinence of detection.

[0106] In some alternative implementation manners of this embodiment, the determination unit 203 is further configured to: calculate a similarity between the code feature and the code feature of the historical secure hot update package of the application to obtain a similarity calculation result; detect whether there are any abnormal behaviors during the runtime of the application after the application hot update package is installed based on the topology information to obtain a first detection result; detect whether there are any abnormal behaviors of the application when the user performs an operation in the application after the application hot update package is installed based on the first behavior data to obtain a second detection result; determine whether the application hot update package is secure based on the similarity calculation result, the first detection result, and the second detection result. By comprehensively considering the similarity calculation result, the first detection result, and the second detection result, multi-dimensional security detection is achieved, which can effectively identify malicious code, runtime abnormal behaviors, and abnormal changes in functional modules in the application hot update package, significantly improving the accuracy and reliability of detection, and enhancing the ability of the application system to resist potential security risks of hot updates.

[0107] In some alternative implementation manners of this embodiment, the determining unit 203 is further configured to: for the function modules in the application hot update package, determine whether the function modules are abnormal based on the first behavior data and the historical behavior data of the application after installing the historical security hot update package, so as to obtain a third detection result; and determine whether the application hot update package is secure based on the similarity calculation result, the first detection result, the second detection result, and the third detection result. By comparing the first behavior data with the historical behavior data, the behavioral changes of the function modules after the update can be comprehensively understood. This method can effectively discover the abnormal update timing, behavioral paths, and dependency relationships of the function modules, improve the depth and breadth of detection, and enhance the ability of the application system to resist potential security risks of hot updates.

[0108] In some alternative implementation manners of this embodiment, the method further includes an updating unit, configured to: install the application hot update package when it is detected that the application hot update package is secure; during the running of the application, obtain the second behavior data of the application; and update the security detection rules for the application hot update package based on the second behavior data. By continuously monitoring the behavior data during the running of the application and dynamically optimizing the security detection rules according to the new data, continuous improvement of the security detection of the application hot update package is achieved. This method can effectively cope with changing security threats, improve the adaptability and accuracy of detection, and enhance the ability of the application system to resist potential security risks of hot updates.

[0109] The device provided in the foregoing embodiment of this application first, when receiving an application hot update package of an application, obtains the code features of the application hot update package; then runs the application in a sandbox environment and installs the application hot update package, and obtains the topology information of the memory space and the first behavior data of the application; and finally determines whether the application hot update package is secure based on the code features, the topology information, and the first behavior data. Among them, through the detection of the code features, static analysis of the application hot update package is realized; after running the application in the sandbox and installing the application hot update package, by detecting the topology information of the memory space and the first behavior data of the application, the behavior of the memory and the application can be monitored in real time, so as to effectively discover dynamic and hidden malicious behaviors, and dynamic analysis of the application hot update package is realized. By combining static analysis and dynamic analysis, multi-dimensional analysis and comprehensive security detection of the application hot update package are realized, the missed detection rate and false detection rate of the security detection of the application hot update package are reduced, and the accuracy of the security detection of the application hot update package is improved.

[0110] The detection device in the embodiments of the present application may be an electronic device or a component in an electronic device, such as an integrated circuit or a chip. The electronic device may be a terminal or other devices other than terminals. Exemplarily, the electronic device may be a mobile phone, a tablet computer, a laptop computer, a handheld computer, a vehicle-mounted electronic device, a Mobile Internet Device (MID), an Augmented Reality (AR) / Virtual Reality (VR) device, a robot, a wearable device, an Ultra-Mobile Personal Computer (UMPC), a netbook, or a Personal Digital Assistant (PDA), etc. It may also be a server, a Network Attached Storage (NAS), a Personal Computer (PC), a Television (TV), a teller machine, or a self-service machine, etc. The embodiments of the present application do not make specific limitations.

[0111] The detection device in the embodiments of the present application may be a device with an operating system. The operating system may be an Android operating system, an iOS operating system, or other possible operating systems. The embodiments of the present application do not make specific limitations.

[0112] The detection device provided by the embodiments of the present application can implement Figure 1 each process implemented by the method embodiments. To avoid repetition, it will not be elaborated here.

[0113] Optionally, as Figure 3 shown, the embodiments of the present application further provide an electronic device 300, including a processor 301 and a memory 302. A program or instruction that can run on the processor 301 is stored on the memory 302. When the program or instruction is executed by the processor 301, it implements each step of the above detection method embodiment and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.

[0114] It should be noted that the electronic devices in the embodiments of the present application include the above-mentioned mobile electronic devices and non-mobile electronic devices.

[0115] Figure 4 It is a schematic hardware structure diagram of an electronic device for implementing the embodiments of the present application.

[0116] The electronic device 400 includes, but is not limited to, components such as a radio frequency unit 401, a network module 402, an audio output unit 403, an input unit 404, a sensor 405, a display unit 406, a user input unit 407, an interface unit 408, a memory 409, and a processor 410.

[0117] Those skilled in the art can understand that the electronic device 400 may further include a power source (such as a battery) for supplying power to each component. The power source can be logically connected to the processor 410 through a power management system, so as to implement functions such as management of charging, discharging, and power consumption management through the power management system. Figure 4 The structure of the electronic device shown does not limit the electronic device. The electronic device may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be elaborated here.

[0118] Among them, the processor 410 is configured to obtain the code features of the application hot update package when receiving the application hot update package of the application; run the application in a sandbox environment and install the application hot update package, and obtain the topology information of the memory space and the first behavior data of the application; determine whether the application hot update package is secure based on the code features, the topology information, and the first behavior data.

[0119] By detecting the code features, static analysis of the application hot update package is realized; after running the application in the sandbox and installing the application hot update package, by detecting the topology information of the memory space and the first behavior data of the application, the memory and the behavior of the application can be monitored in real time, so as to effectively discover dynamic and hidden malicious behaviors, and dynamic analysis of the application hot update package is realized. By combining static analysis and dynamic analysis, multi-dimensional analysis and comprehensive security detection of the application hot update package are realized, the missed detection rate and false detection rate of the security detection of the application hot update package are reduced, and the accuracy of the security detection of the application hot update package is improved.

[0120] Optionally, the processor 410 is further configured to convert the code of the application hot update package into an abstract syntax tree; extract structured information from the abstract syntax tree, where the structured information includes at least one of the following: control flow graph, data dependency information, depth information of the function call tree; perform conversion processing on the structured information through a graph embedding algorithm to obtain code features. By converting the code of the application hot update package into an abstract syntax tree and extracting structured information, the semantic features of the code can be captured more accurately. By converting the structured information into a high-dimensional vector through a graph embedding algorithm to generate code features, it is convenient for subsequent similarity calculation and anomaly detection.

[0121] Optionally, the processor 410 is further configured to obtain memory access data by using a page table mapping redirection technique. The memory access data includes at least one of the following: allocation data of the heap memory, stack frame timing change data, and call data of the target interface. Based on the memory access data, topological information of the memory space is generated. By obtaining memory access data by using the page table mapping redirection technique and generating topological information of the memory space, the memory usage of the application hot update package during runtime can be comprehensively understood. This method can effectively detect hidden malicious behaviors, such as heap spraying attacks, abnormal stack frame inflation, and covert dependency injection, improving the depth and breadth of detection.

[0122] Optionally, the processor 410 is further configured to obtain historical operation information of the user in the application; perform an operation on the application based on the historical operation information in a sandbox environment, and obtain first behavior data generated by the application in response to the operation. By obtaining the historical operation information of the user in the application and performing an operation on the application based on the historical operation in a sandbox environment, the dynamic behavior of the update module in the actual usage scenario can be comprehensively understood. This method can effectively detect abnormal behaviors of the update module under user operations, such as sensitive operation chains, abnormal control flows, and resource competition behaviors, improving the practicality and pertinence of detection.

[0123] Optionally, the processor 410 is further configured to calculate the similarity between the code feature and the code feature of the historical secure hot update package of the application to obtain a similarity calculation result; based on the topological information, detect whether there are abnormal behaviors when the application is running after the application hot update package is installed to obtain a first detection result; based on the first behavior data, detect whether there are abnormal behaviors when the user performs an operation in the application after the application hot update package is installed to obtain a second detection result; based on the similarity calculation result, the first detection result, and the second detection result, determine whether the application hot update package is secure. By comprehensively considering the similarity calculation result, the first detection result, and the second detection result, multi-dimensional security detection is achieved, which can effectively identify malicious codes, runtime abnormal behaviors, and abnormal changes in functional modules in the application hot update package, significantly improving the accuracy and reliability of detection, and enhancing the ability of the application system to resist potential security risks of hot updates.

[0124] Optionally, the processor 410 is further configured to determine whether a function module in the application hot update package is abnormal based on the first behavior data and the historical behavior data of the application after installing the historical security hot update package, so as to obtain a third detection result; and determine whether the application hot update package is secure based on the similarity calculation result, the first detection result, the second detection result, and the third detection result. By comparing the first behavior data with the historical behavior data, the behavioral changes of the function module after the update can be comprehensively understood. This method can effectively detect abnormal update timings, behavioral paths, and dependency relationships of function modules, improve the depth and breadth of detection, and enhance the ability of the application system to resist potential security risks of hot updates.

[0125] Optionally, the processor 410 is further configured to install the application hot update package when it is detected that the application hot update package is secure; during the running of the application, obtain second behavior data of the application; and update the security detection rules for the application hot update package based on the second behavior data. By continuously monitoring the behavior data during the running of the application and dynamically optimizing the security detection rules according to new data, continuous improvement of the security detection of the application hot update package is achieved. This method can effectively cope with constantly changing security threats, improve the adaptability and accuracy of detection, and enhance the ability of the application system to resist potential security risks of hot updates.

[0126] It should be understood that in the embodiments of the present application, the input unit 404 may include a graphics processing unit (GPU) 4041 and a microphone 4042. The graphics processing unit 4041 processes image data of static pictures or videos obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode. The display unit 406 may include a display panel 4061, and the display panel 4061 may be configured in the form of a liquid crystal display, an organic light-emitting diode, etc. The user input unit 407 includes at least one of a touch panel 4071 and other input devices 4072. The touch panel 4071 is also referred to as a touch screen. The touch panel 4071 may include two parts: a touch detection device and a touch controller. The other input devices 4072 may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, power on / off keys, etc.), a trackball, a mouse, and a joystick, which will not be elaborated herein.

[0127] The memory 409 can be used to store software programs and various data. The memory 409 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data. Among them, the first storage area may store an operating system, application programs or instructions required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory 409 may include a volatile memory or a non-volatile memory, or the memory 409 may include both a volatile memory and a non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDR SDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synch link dynamic random access memory (SLDRAM), and a direct rambus random access memory (DRRAM). The memory 409 in the embodiments of the present application includes but is not limited to these and any other suitable types of memories.

[0128] The processor 410 may include one or more processing units; optionally, the processor 410 integrates an application processor and a modem processor. Among them, the application processor mainly processes operations related to the operating system, user interface, and application programs, etc., and the modem processor mainly processes wireless communication signals, such as a baseband processor. It can be understood that the above modem processor may not be integrated into the processor 410 either.

[0129] The embodiments of the present application also provide a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, it implements each process of the above detection method embodiment and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.

[0130] Among them, the processor is the processor in the electronic device described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory ROM, random access memory RAM, magnetic disks, or optical discs, etc.

[0131] Another embodiment of the present application provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement each process of the above detection method embodiment and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.

[0132] It should be understood that the chip mentioned in the embodiments of the present application may also be referred to as a system-on-chip, system chip, chip system, or system-on-chip, etc.

[0133] The embodiments of the present application provide a computer program product. The program product is stored in a storage medium and is executed by at least one processor to implement each process of the above detection method embodiment and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.

[0134] It should be noted that in this article, the term "including", "comprising", or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article, or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article, or device. Without more limitations, the element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, article, or device including the element. In addition, it should be pointed out that the methods and devices in the embodiments of the present application are not limited to performing functions in the order shown or discussed. They may also include performing functions in a substantially simultaneous manner or in the reverse order according to the functions involved. For example, the described methods may be performed in an order different from that described, and various steps may be added, omitted, or combined. Additionally, the features described with reference to certain examples may be combined in other examples.

[0135] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-described embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, can be embodied in the form of a computer software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions for causing a terminal (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in various embodiments of the present application.

[0136] The embodiments of the present application have been described above in conjunction with the accompanying drawings. However, the present application is not limited to the above specific implementation manners. The above specific implementation manners are merely illustrative and not restrictive. Under the inspiration of the present application, those of ordinary skill in the art can also make many forms without departing from the purpose of the present application and the scope protected by the claims, and all of them belong to the protection scope of the present application.

Claims

1. A detection method, characterized in that, The method includes: When receiving an application hot update package of an application, obtaining the code features of the application hot update package; Running the application in a sandbox environment and installing the application hot update package, obtaining the topological information of the memory space and the first behavior data of the application; Based on the code features, the topological information, and the first behavior data, determining whether the application hot update package is secure.

2. The method according to claim 1, characterized in that, The obtaining the code features of the application hot update package includes: Converting the code of the application hot update package into an abstract syntax tree; Extracting structured information from the abstract syntax tree, where the structured information includes at least one of the following: topological information of a control flow graph, data dependency relationship information, depth information of a function call tree; Performing a conversion process on the structured information through a graph embedding algorithm to obtain code features.

3. The method according to claim 1, wherein The obtaining the topological information of the memory space includes: Adopting a page table mapping redirection technique to obtain memory access data, where the memory access data includes at least one of the following: allocation data of heap memory, stack frame timing change data, call data of a target interface; Based on the memory access data, generating the topological information of the memory space.

4. The method according to claim 1, wherein Obtaining the first behavior data of the application hot update package includes: Obtaining the historical operation information of a user in the application; Performing an operation on the application in a sandbox environment based on the historical operation information, and obtaining the first behavior data generated by the application in response to the operation.

5. The method according to any one of claims 1 to 4, characterized in that The determining whether the application hot update package is secure based on the code features, the topological information, and the first behavior data includes: Calculating the similarity between the code features and the code features of the historical secure hot update package of the application to obtain a similarity calculation result; Based on the topological information, detecting whether there is an abnormal behavior when the application is running after the application hot update package is installed to obtain a first detection result; Based on the first behavior data, detecting whether there is an abnormal behavior of the application when the user performs an operation in the application after the application hot update package is installed to obtain a second detection result; Based on the similarity calculation result, the first detection result, and the second detection result, determining whether the application hot update package is secure.

6. The method according to claim 5, characterized in that, The determining whether the application hot update package is secure based on the similarity calculation result, the first detection result, and the second detection result includes: For a functional module in the application hot update package, based on the first behavior data and the historical behavior data of the application after installing the historical secure hot update package, determining whether the functional module is abnormal to obtain a third detection result; Based on the similarity calculation result, the first detection result, the second detection result, and the third detection result, determining whether the application hot update package is secure.

7. A detection device, characterized in that, The apparatus includes: A first obtaining unit, configured to obtain the code features of the application hot update package when receiving an application hot update package of an application; A second obtaining unit, configured to run the application in a sandbox environment and install the application hot update package, and obtain the topological information of the memory space and the first behavior data of the application; A determination unit, configured to determine whether the application hot update package is secure based on the code feature, the topology information, and the first behavior data.

8. The device according to claim 7, wherein The first acquisition unit is further configured to: Convert the code of the application hot update package into an abstract syntax tree; Extract structured information from the abstract syntax tree, where the structured information includes at least one of the following: control flow graph, data dependency information, depth information of the function call tree; Perform conversion processing on the structured information through a graph embedding algorithm to obtain a code feature.

9. The device according to claim 7, characterized in that, The second acquisition unit is further configured to: Adopt a page table mapping redirection technique to obtain memory access data, where the memory access data includes at least one of the following: allocation data of heap memory, stack frame timing change data, call data of the target interface; Generate topology information of the memory space based on the memory access data.

10. The device according to claim 7, characterized in that, The second acquisition unit is further configured to: Obtain the historical operation information of the user in the application; Perform an operation on the application in a sandbox environment based on the historical operation information, and obtain the first behavior data generated by the application in response to the operation.

11. The device according to any one of claims 7-10, characterized in that, The detection unit is further configured to: Calculate the similarity between the code feature and the code feature of the historical secure hot update package of the application to obtain a similarity calculation result; Based on the topology information, detect whether there is an abnormal behavior during the running of the application after the installation of the application hot update package to obtain a first detection result; Based on the first behavior data, detect whether there is an abnormal behavior of the application when the user performs an operation in the application after the installation of the application hot update package to obtain a second detection result; Determine whether the application hot update package is secure based on the similarity calculation result, the first detection result, and the second detection result.

12. The device according to claim 11, characterized in that, The detection unit is further configured to: For the functional module in the application hot update package, determine whether the functional module is abnormal based on the first behavior data and the historical behavior data of the application after installing the historical secure hot update package to obtain a third detection result; Determine whether the application hot update package is secure based on the similarity calculation result, the first detection result, the second detection result, and the third detection result.

Citation Information

Cited By

  • Recognition and protection method, device and equipment for kernel stack spraying, medium and product

    CN121071867A