Application compliance detection method, electronic equipment, storage medium and program product
By analyzing the application's dependency information and call chain data, the matching degree of the target interface's call information and privacy rights declarations is automatically detected, solving the problems of low efficiency and low accuracy in the existing technology, and achieving efficient and accurate application compliance detection.
Patent Information
- Application Number
- CN202510387021.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-07-29
AI Technical Summary
In the prior art, application compliance detection relies on manual sorting and third-party SDK self-inspection, resulting in low detection efficiency and low accuracy, and the inability to effectively ensure the compliance of the application's privacy call.
By analyzing the application's dependency information, generating an SDK information list, obtaining call chain data, analyzing the call chain relationship, detecting the matching degree between the call information of the target interface and the privacy rights declaration, and automatically detecting the application's compliance.
It realizes efficient and accurate application compliance detection, supports fine-grained analysis, improves detection efficiency and accuracy, and can quickly locate potential privacy interface call risks.
Smart Images

Figure CN120387186A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technology, and particularly to a method for detecting the compliance of an application, an electronic device, a storage medium, and a program product. Background Art
[0002] To ensure the privacy and security of users, applications (apps) often need to undergo compliance detection to check the privacy invocation situations of the applications according to the regulations of relevant policies and ensure the compliance of privacy invocations.
[0003] However, some applications involve many services, which may be services introduced by third-party SDKs (Software Development Kits, abbreviated as SDKs) of different service providers. For this type of application, compliance detection often can only collect the compliance information self-verified by the service providers in the form of a collection table, and the efficiency and accuracy of compliance detection are relatively low. Summary of the Invention
[0004] The present disclosure provides a method for detecting the compliance of an application, an electronic device, a storage medium, and a program product.
[0005] According to one aspect of the present disclosure, there is provided a method for detecting the compliance of an application, including: Parsing the dependency information of the application to obtain a list of SDK information; Obtaining, from the list of SDK information, call chain data for describing the call relationship between methods of the application; Parsing the call chain data to obtain the call chain of each method in the list of SDK information, so as to obtain a set of SDK call chains; Obtaining the mapping relationship between the target call chain and the SDK from the set of SDK call chains and using it as the call information of the target interface called by the target call chain; Detecting the matching degree between the call information of the target interface and the privacy permission statement of the application to obtain a matching degree detection result; If the matching degree detection result is a first result indicating that the call information of the target interface does not match the privacy permission statement of the application, determining that the application is non-compliant.
[0006] According to the method for detecting the compliance of an application according to at least one embodiment of the present disclosure, parsing the dependency information of the application to obtain a list of SDK information includes: Parsing the dependency information of the application to extract third-party SDK metadata as first data; If the dependency information of the application includes local dependencies, scanning the local project path to extract locally integrated SDK data as second data; Perform data deduplication on the first data and the second data, and use the first data and the second data after data deduplication as the SDK information list.
[0007] According to the compliance detection method of an application according to at least one embodiment of the present disclosure, parsing the dependency information of the application to obtain an SDK information list further includes: If the dependency information of the application does not include local dependencies, skip scanning the local project path and use the first data as the SDK information list.
[0008] According to the compliance detection method of an application according to at least one embodiment of the present disclosure, obtaining the call chain data of the application from the SDK information list includes: Traverse the file paths in the SDK information list to find binary executable files in the file paths; Obtain the methods corresponding to the symbol information in the binary executable file; Establish a correspondence between the methods corresponding to the symbol information and the SDKs in the SDK information list; Based on the correspondence, determine the static call path and the dynamic call path of the SDKs in the SDK information list, and use the determined static call path and dynamic call path as the call chain data of the application.
[0009] According to the compliance detection method of an application according to at least one embodiment of the present disclosure, parsing the call chain data to obtain the call chain of each method in the SDK information list to obtain an SDK call chain set includes: Parse the call chain data to obtain the call relationship between classes and methods; Recursively traverse the call chains of the methods in each of the call relationships to obtain the SDK call chain set.
[0010] According to the compliance detection method of an application according to at least one embodiment of the present disclosure, obtaining the mapping relationship between the target call chain and the SDK from the SDK call chain set and using it as the call information of the target interface called by the target call chain includes: Determine the class and method corresponding to the target interface; Based on the class and method corresponding to the target interface, filter out the target call chain in the SDK call chain set; Split the individual methods in the target call chain as target methods; Query the SDK to which the target method belongs; If the SDK to which the target method belongs is queried, determine the queried SDK as the target SDK; Generate a mapping relationship between the target call chain and the SDK corresponding to the same target method as the call information of the target interface.
[0011] According to the compliance detection method of the application according to at least one embodiment of the present disclosure, detect the matching degree between the call information of the target interface and the privacy permission statement of the application, and obtain a matching degree detection result, including: When the target interface is a privacy interface, if any SDK in the call information of the privacy interface is not in the privacy permission statement of the application, it is determined that the call information of the target interface does not match the privacy permission statement of the application, and the first result is used as the matching degree detection result; Or when the target interface is a privacy interface, if any SDK in the privacy permission statement of the application is not in the call information of the privacy interface, it is determined that the call information of the target interface does not match the privacy permission statement of the application, and the first result is used as the matching degree detection result.
[0012] According to another aspect of the present disclosure, an electronic device is provided, including: a memory that stores execution instructions; and a processor that executes the execution instructions stored in the memory, so that the processor executes the compliance detection method of the application according to any one of the embodiments of the present disclosure.
[0013] According to still another aspect of the present disclosure, a readable storage medium is provided, in which execution instructions are stored, and when the execution instructions are executed by a processor, they are used to implement the compliance detection method of the application according to any one of the embodiments of the present disclosure.
[0014] According to yet another aspect of the present disclosure, a computer program product is provided, including a computer program, and when the computer program is executed by a processor, it implements the compliance detection method of the application according to any one of the embodiments of the present disclosure. Description of the Drawings
[0015] The drawings illustrate exemplary embodiments of the present disclosure and are used together with the description to explain the principles of the present disclosure, including these drawings to provide a further understanding of the present disclosure, and the drawings are included in this specification and form a part of this specification.
[0016] Figure 1 It is a flowchart of the compliance detection method of the application according to an embodiment of the present disclosure.
[0017] Figure 2 It is a flowchart of the compliance detection method of the application according to an embodiment of the present disclosure.
[0018] Figure 3It is a schematic flowchart of a compliance detection method for an application according to an embodiment of the present disclosure.
[0019] Figure 4 It is a schematic flowchart of a compliance detection method for an application according to an embodiment of the present disclosure.
[0020] Figure 5 It is a schematic flowchart of a compliance detection method for an application according to an embodiment of the present disclosure.
[0021] Figure 6 It is a schematic flowchart of a compliance detection method for an application according to an embodiment of the present disclosure.
[0022] Figure 7 It is a schematic flowchart of a compliance detection method for an application according to an embodiment of the present disclosure.
[0023] Figure 8 It is a schematic block diagram of the structure of a compliance detection device for an application according to an embodiment of the present disclosure.
[0024] Figure 9 It is a schematic block diagram of the structure of an electronic device according to an embodiment of the present disclosure. Specific embodiments
[0025] The present disclosure will be further described in detail below with reference to the accompanying drawings and examples. It can be understood that the specific examples described herein are only used to explain the relevant content and do not limit the present disclosure. In addition, it should be noted that for the sake of convenience of description, only parts related to the present disclosure are shown in the accompanying drawings.
[0026] It should be noted that, without conflict, the embodiments in the present disclosure and the features in the embodiments can be combined with each other. The technical solutions of the present disclosure will be described in detail below with reference to the accompanying drawings and embodiments.
[0027] According to relevant policy regulations, it is necessary to perform compliance detection on applications (apps) to ensure the compliance of privacy calls of the applications. However, the current compliance detection relies on manual sorting and investigation, and when a third-party SDK (Software Development Kit, abbreviated as: SDK) is introduced into the application, the business party providing the SDK file needs to self-check and evaluate the privacy compliance and report it to the application. The entire compliance detection process has problems such as a long cycle, low efficiency, and low accuracy.
[0028] The embodiments of the present disclosure provide a compliance detection method for an application, and this method can be executed by an electronic device such as a computer, a mobile phone, a smart wearable device, and a smart home appliance that can install application programs. The compliance detection method for an application in the embodiments of the present disclosure is mainly used to detect the privacy call compliance of the application.
[0029] The compliance detection method for applications in the embodiments of the present disclosure can be applicable to applications running on systems such as the Android system, the iOS system, and the HarmonyOS system. For the sake of convenience of description, this article takes the compliance detection method applied to an application running on the iOS system as an example for introduction, and the relevant files involved in the embodiments are iOS system files. When applied to the Android system or the HarmonyOS system, the operating environment of the Android system or the HarmonyOS system can be correspondingly replaced based on the embodiments provided in this article.
[0030] Figure 1 FIG. shows a schematic diagram of the overall process of the compliance detection method M10 for applications in an embodiment of the present disclosure. As Figure 1 shown, the method includes steps S11 to S16.
[0031] Specifically, Figure 1 the method shown includes: S11. Analyze the dependency information of the application to obtain a list of SDK information.
[0032] Among them, the dependency information of the application usually includes information such as the name, version number, and source of the SDK, and this information can be obtained from the installation package of the application. Based on the parsed information such as the name, version number, and source of each SDK, a list of SDK information for the application can be generated. For example, the Podfile.lock file of the iOS system contains the dependency information of the application, and parsing the Podfile.lock file can obtain a list of SDK information for the application. In this way, all the SDKs used in the application and their version information can be clarified, and a structured SDK dependency list can be obtained, providing basic data for subsequent analysis.
[0033] S12. Obtain the call chain data for describing the call relationship between methods of the application from the list of SDK information.
[0034] Among them, the call chain data of the application is used to describe the detailed call relationship between methods. In this way, call relationship data at the method level can be provided to support fine-grained analysis.
[0035] S13. Analyze the call chain data to obtain the call chain of each method in the list of SDK information, so as to obtain a set of SDK call chains.
[0036] Among them, the set of SDK call chains includes the set of call chains of each method in the list of SDK information.
[0037] The purpose of step S13 is to sort out the call chain corresponding to each method from the call chain data to obtain a set of SDK call chains. In this way, the call path of each method can be clarified, which can support in-depth analysis and ensure that no call relationship is missed.
[0038] S14. Obtain the mapping relationship between the target call chain and the SDK from the SDK call chain set, and use it as the call information of the target interface called by the target call chain.
[0039] Among them, the target call chain can be the call chain of a privacy interface (API). In this case, the target interface called by the target call chain is a privacy interface. A privacy interface is an interface used to process and protect user personal information. Through the privacy interface, user privacy data can be accessed. Therefore, calls involving privacy interfaces need to be carefully checked to ensure their compliance.
[0040] Each call chain in the SDK call chain set obtained through step S13 corresponds to a method. Based on this, in an example, the call chains corresponding to the methods involved in the privacy interface can be filtered out from the SDK call chain set according to the methods involved in the pre-collected privacy interface, and they are recorded as the target call chains.
[0041] On the basis of obtaining the target call chain, the corresponding relationship between the method represented by the target call chain and the SDK constitutes the mapping relationship between the target call chain and the SDK. This dependency relationship is used as the call information of the privacy interface. In this way, the call path and source of the privacy interface can be clarified, which is convenient for positioning to support accurate compliance detection and improve the efficiency of compliance detection.
[0042] S15. Detect the matching degree between the call information of the target interface and the privacy permission statement of the application to obtain the matching degree detection result.
[0043] Among them, the privacy permission of the application refers to the permissions related to privacy information that need to be requested from the user in the application. These permissions define the types and scopes of user data and system resources that the program can access. The privacy permission statement of the application refers to the visible description shown to the user when the application requests privacy permissions, which is used to publicly disclose the privacy permissions that the application needs to use. In the IOS system, the privacy permission statement of the application can be extracted from the Info.plist file.
[0044] The purpose of step S15 is to compare whether the permission scopes of the call information of the target interface and the privacy permission statement of the application match. The call information of the target interface includes information such as the call path and source of the target interface. If the call information of the target interface does not match the permission scope defined in the privacy permission statement, there may be a risk of privacy leakage. Based on this, the matching degree detection result can be used to determine whether the permission scopes of the call information of the target interface and the privacy permission statement of the application match, so as to help judge whether the application is compliant. The comparison method of the matching degree detection has high accuracy and is simple and fast, which can improve the efficiency of compliance detection.
[0045] S16. If the result of the matching degree detection is the first result indicating that the call information of the target interface does not match the privacy permission statement of the application, determine that the application is non-compliant.
[0046] Among them, the first result indicates a mismatch between the call information of the target interface and the permission statement of the application. That is to say, when the result of the matching degree detection is the first result, it indicates that the permission scopes of the call information of the target interface and the privacy permission statement of the application do not match, and it is determined that the application is non-compliant.
[0047] In summary, the compliance detection method for the application of the embodiments of the present disclosure can obtain the dependency information of the application by scanning the installation package of the application, and output the complete call information of the target interface based on the dependency information of the application for the detection of the permission matching degree, and then determine the compliance of the application according to the result of the matching degree detection. In this way, automated compliance detection can be supported, with high detection efficiency and accuracy. All files in the detection process can be obtained by scanning. The SDK information list, call chain set, call information, and other data output in the intermediate process are all structured data, which support quick positioning and can improve the efficiency of compliance detection.
[0048] Regarding step S11, in some embodiments of the present disclosure, it may include steps S111 to S113 as Figure 2 shown.
[0049] S111. Analyze the dependency information of the application and extract the third-party SDK metadata as the first data.
[0050] The first data is data related to the third-party SDK, and may include information such as the name, version number, and source of the third-party SDK.
[0051] In one example, the dependency information of the application includes the dependencies in the Podfile.lock file, and the first data can be obtained by analyzing the Podfile.lock file. Specifically, the Podfile.lock file is in YAML format, and the SnakeYAML library can be used to parse it into structured data, and data such as POD dependencies (PODS), specification libraries (SPEC REPOS), and checkout options (CHECKOUT OPTIONS) can be extracted from the parsed YAML data. The name and version number of the third-party SDK can be extracted by analyzing the POD dependencies; the specification library is used to provide the source of the third-party SDK; the checkout option contains the checkout information of the POD dependencies, such as the commit hash or branch of the Git repository, which can help to further determine the SDK version. In this way, by analyzing the Podfile.lock file, the third-party SDK metadata can be automatically extracted with high efficiency.
[0052] S112. If the dependency information of the application contains local dependencies, scan the local project path and extract the SDK data integrated locally as the second data.
[0053] The second data is data related to the local SDK, which may include information such as the name, version number, and source of the local SDK.
[0054] Local dependencies are local library files introduced in the application project, such as ".framework" files, ".xcframework" files, etc. In one example, if the dependency information of the application contains a local directory, it can be determined that the dependency information of the application contains local dependencies.
[0055] When extracting the second data, the specified local project directory can be traversed to find folders ending with ".framework" or ".xcframework". For each found folder, read the Info.plist file therein to parse fields such as CFBundleShortVersionString or CFBundleVersion to obtain data such as the name and version number of the local SDK; find the Mach-O file therein, calculate the MD5 hash value of the Mach-O file for identity recognition of the local SDK, and then save information such as the name, version number, Mach-O file path, and MD5 hash value of the local SDK as the second data.
[0056] S113. Perform data deduplication on the first data and the second data, and use the deduplicated first data and second data as the SDK information list.
[0057] Since the sources of the first data and the second data are different, coming from a third party and the current system local respectively, there may be some duplicate data. The purpose of step S113 is to perform data deduplication on the first data and the second data to merge the duplicate data into unique data, and then save the deduplicated first data and second data as the SDK information list. In this way, the storage occupancy of the SDK information list can be reduced, and it can prevent duplicate calculations caused by querying duplicate data when querying the SDK information list.
[0058] In one embodiment, data deduplication can be performed based on information such as the name of the SDK and the MD5 hash value corresponding to the SDK, and SDKs with the same name or MD5 hash value can be merged.
[0059] In summary, steps S111 to S113 can not only scan the SDKs of third-party dependencies but also scan the SDKs of local dependencies, ensuring that all dependencies involved in the application are included in the SDK information list for compliance detection.
[0060] Regarding step S11, in some embodiments of the present disclosure, it may include step S114 as Figure 3 shown.
[0061] S114. If the dependency information of the application does not include local dependencies, skip the scanning of the local project path and use the first data as the SDK information list.
[0062] If the dependency information of the application does not include local dependencies, for example, the dependency information of the application does not include a local directory, the scanning of the local project path can be skipped, and only the first data is used as the SDK information list, saving the time for extracting the second data and performing the deduplication process, and improving the efficiency of compliance detection.
[0063] Regarding step S12, in some embodiments of the present disclosure, it may further include steps S121 to S124 as Figure 4 shown.
[0064] S121. Traverse the file paths in the SDK information list to find the binary executable files in the file paths.
[0065] The file paths in the SDK information list include the paths of POD dependencies managed by CocoaPods. If the second data is included in the SDK information list, the local project path should also be traversed. In the IOS system, the binary executable file is a Mach-O file.
[0066] S122. Obtain the methods corresponding to the symbol information in the binary executable file.
[0067] In the IOS system, the nm command can be called to extract the symbol information from the Mach-O file, and the symbols representing methods can be obtained from it, including the symbols representing instance methods and the symbols representing class methods. Based on the obtained symbols representing methods, the name of the method represented by the symbols can be determined, and thus the methods corresponding to the symbol information can be obtained.
[0068] S123. Establish the correspondence between the methods corresponding to the symbol information and the SDKs in the SDK information list.
[0069] The symbol information is the information extracted from the Mach-O file of the SDK in the SDK information list. Therefore, the methods corresponding to the symbol information correspond to the SDK where the Mach-O file to which the symbol information belongs is located, and thus the correspondence between the methods and the SDKs can be established. In this way, during the business call process of the application, the call chain data of the application can be obtained by tracking the methods and SDKs with the corresponding relationship.
[0070] S124. Determine the static call path and dynamic call path of the SDKs in the SDK information list based on the corresponding relationship, and use the determined static call path and dynamic call path as the call chain data of the application.
[0071] In one example, a static analysis tool, such as the clang -analyze tool, Hopper Disassembler tool, etc., can be used to analyze the call relationships between code blocks of the application to obtain the static call path. Then, based on the corresponding relationship between the methods and the SDKs, determine the SDKs corresponding to the methods in the static call path to mark the boundaries of each SDK in the static call path.
[0072] In one example, a instrumentation tool, such as the dtrace tool, LLDB tool, etc., can be used to capture the real call sequence of the application to obtain the stack address as the dynamic call path. Then, perform symbolic parsing on the stack address, convert the stack address into a symbol, obtain the method name represented by the converted symbol, and determine the corresponding SDK based on the corresponding relationship between the method and the SDK to mark the boundaries of each SDK in the dynamic call path.
[0073] In summary, the static call path and dynamic call path marked with SDK boundaries constitute the call chain data of the application, and each SDK in the call chain data corresponds to at least one method.
[0074] Regarding step S13, in some embodiments of the present disclosure, it may include steps S131 to S132 as Figure 5 shown.
[0075] S131. Analyze the call chain data to obtain the call relationships between classes and methods.
[0076] By understanding the call relationships between classes and methods in the application, potential privacy interface call paths can be identified to ensure comprehensive coverage of compliance detection and improve the accuracy of compliance detection.
[0077] In one embodiment, a graph storage structure can be used to convert the call chain data into a call relationship graph, then perform pruning processing on the call relationship graph to merge duplicate paths therein, and parse the pruned call graph. Based on the paths between classes and methods in the call relationship graph, obtain the call relationships between classes and methods.
[0078] S132. Recursively traverse the call chains of the methods in each call relationship to obtain a set of SDK call chains.
[0079] The call relationship between classes and methods can serve as the starting point for call chain analysis. In one embodiment, one can start from a method in a certain call relationship and recursively analyze each call chain it involves until reaching the maximum call depth, and then return the set of call chains of this method. And so on, recursively analyze each method in the SDK information list to obtain the set of call chains for each method respectively, and generate an SDK call chain set based on the set of call chains for each method respectively.
[0080] In one embodiment, a graph storage structure can be used to convert the SDK call chain set into a call chain graph to provide a visual call path, facilitating the developers of the application to locate specific call chains.
[0081] Regarding step S14, in some embodiments of the present disclosure, it may include steps S141 to S146 as Figure 6 shown.
[0082] S141. Determine the class and method corresponding to the target interface.
[0083] The class and method corresponding to the target interface can be collected and stored in advance before executing the compliance detection method M10 of the application. When executing step S141, determine the class and method corresponding to the target interface from the information stored in advance.
[0084] In one example, the target interface is a privacy interface. The class and method corresponding to the privacy interface may include classes and methods involved in frameworks such as Bluetooth, location, calendar, camera, album, address book, face, microphone, sensor, etc., which will not be listed one by one here.
[0085] S142. Based on the class and method corresponding to the target interface, filter out the target call chains from the SDK call chain set.
[0086] Given the class and method corresponding to the target interface, based on the class and method corresponding to the target interface, each call chain involved in the class and method corresponding to the target interface can be filtered out as the target call chain.
[0087] S143. Split the individual methods in the target call chain as the target methods.
[0088] In one embodiment, the string of the target call chain can be split into individual methods as the target methods with the method separation symbol as the boundary. In this way, it is convenient to analyze the SDK to which each individual method belongs one by one, ensuring a clear correspondence between the method and the SDK, and improving the accuracy of compliance detection.
[0089] S144. Query the SDK to which the target method belongs.
[0090] In one example, based on the method identifier of the SDK extracted in the previous steps, the SDK to which the method identifier corresponding to the target method belongs can be queried to determine the SDK to which the target method belongs. If the target method successfully matches the recorded method identifier, record the SDK to which the method identifier belongs as the SDK to which the target method belongs; otherwise, if the match fails, skip the recording.
[0091] S145. If the SDK to which the target method belongs is queried, determine the queried SDK as the target SDK.
[0092] In one example, if the SDK to which the target method belongs is recorded, it indicates that the SDK to which the target method belongs is queried, triggering the response of step S145. At this time, determine the recorded SDK to which the target method belongs as the target SDK.
[0093] S146. Generate a mapping relationship between the target call chain and the target SDK corresponding to the same target method as the call information of the target interface.
[0094] That is to say, if a target SDK and a target call chain correspond to the same target method, it is considered that this target SDK and the target call chain are determined to have a mapping relationship and record the mapping relationship between the two. Since the target call chain is the call chain related to the classes and methods involved in the target interface, therefore, according to the mapping relationship between the target call chain and the SDK, the SDK that actually calls the target interface can be determined to obtain the actual call information of the target interface. Conversely, if the SDK of the application is the SDK involved in the call information of the target interface, the target interface actually called by the SDK can be determined.
[0095] Regarding step S15, in some embodiments of the present disclosure, it may include at least one of step S151 and step S152 as Figure 7 shown.
[0096] Step S151. When the target interface is a privacy interface, if any SDK in the call information of the privacy interface is not in the privacy permission statement of the application, determine that the call information of the target interface does not match the privacy permission statement of the application, and use the first result as the match degree detection result.
[0097] In one embodiment, the match degree detection is to compare whether the SDK in the call information of the privacy interface matches the SDK in the privacy permission statement of the application.
[0098] When any SDK in the call information of the privacy interface is not in the privacy permission statement, it indicates that there is an SDK that is not declared but actually called, and this SDK is involved in the call of the privacy interface. In this case, the matching degree detection result is unmatched, and the first result is obtained. Combining with step S16, it can be determined that the application is non-compliant.
[0099] Step S152: When the target interface is a privacy interface, if any SDK in the privacy permission statement of the application is not in the call information of the privacy interface, it is determined that the call information of the target interface does not match the privacy permission statement of the application, and the first result is used as the matching degree detection result.
[0100] When any SDK in the privacy permission statement of the application is not in the call information of the privacy interface, it indicates that the SDK is declared but not actually called, and this SDK is involved in the call of the privacy interface. In this case, the matching degree detection result is unmatched, and the first result is obtained. Combining with step S16, it can be determined that the application is non-compliant.
[0101] If each SDK in the privacy permission statement of the application is in the call information of the privacy interface, it indicates that each SDK involved in the call of the privacy interface matches the SDK in the privacy permission statement of the application. In this case, the matching degree detection result is matched, and the second result is obtained. According to the second result, it can be determined that the application is compliant.
[0102] Based on any of the above embodiments, the present disclosure also provides a compliance detection device for an application. Figure 8 It is a structural schematic block diagram of a compliance detection device for an application according to an embodiment of the present disclosure.
[0103] As Figure 8 shown, the compliance detection device for the application includes: A dependency parsing module 110, configured to parse the dependency information of the application to obtain a list of SDK information.
[0104] A symbol extraction module 120, configured to obtain call chain data for describing the call relationship between methods of the application from the list of SDK information.
[0105] A call chain parsing module 130, configured to parse the call chain data to obtain the call chain of each method in the list of SDK information, so as to obtain a set of SDK call chains.
[0106] A call information acquisition module 140, configured to obtain the mapping relationship between the target call chain and the SDK from the set of SDK call chains and use it as the call information of the target interface called by the target call chain.
[0107] A matching degree detection module 150 is configured to detect the matching degree between the call information of the target interface and the privacy permission statement of the application, and obtain a matching degree detection result.
[0108] A compliance judgment module 160 is configured to determine that the application is non-compliant if the matching degree detection result is a first result indicating that the call information of the target interface does not match the privacy permission statement of the application.
[0109] The above-mentioned compliance detection device of the application may be computer software, and each module thereof may be a computer software module. The implementation processes of the functions and roles of each module in the above-mentioned compliance detection device of the application are specifically described in the implementation processes of the corresponding steps in the above-mentioned method, and will not be elaborated here.
[0110] The execution subject of the compliance detection method of the application in the specific implementation manner of the present disclosure may be an electronic device such as a server.
[0111] Based on any of the above embodiments, the present disclosure further provides an electronic device, which can execute the compliance detection method of the application in any of the above embodiments described in the present disclosure.
[0112] Figure 9 It is a structural schematic diagram of an electronic device 1000 according to an embodiment of the present disclosure.
[0113] The hardware structure of the electronic device 1000 can be implemented by using a bus architecture. The bus architecture can include any number of interconnected buses and bridges, depending on the specific application of the hardware and the overall design constraints. The bus 1100 connects various circuits including one or more processors 1200, a memory 1300, and / or hardware modules together. The bus 1100 can also connect various other circuits 1400 such as peripheral devices, voltage regulators, power management circuits, external antennas, etc.
[0114] The bus 1100 can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Component (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of simplicity, only one connection line is shown in this figure, but it does not mean that there is only one bus or one type of bus.
[0115] The present disclosure also provides a readable storage medium storing a computer program, which is used to implement the above method when executed by a processor. The "readable storage medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device. More specific examples of the readable storage medium include the following: an electrical connection part with one or more wirings (electronic device), a portable computer disk cartridge (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable read-only memory (CDROM), etc.
[0116] The present disclosure also provides a computer program product. The method of the present disclosure can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed, the processes or functions of the present disclosure are executed in whole or in part.
[0117] The computer program or instructions can be stored in a readable storage medium, or transmitted from one readable storage medium to another. For example, the computer program or instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired or wireless manner. The readable storage medium can be any accessible available medium or a data storage device such as a server or data center integrating one or more available mediums. The available medium can be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; it can also be an optical medium, such as a digital video disc; or it can be a semiconductor medium, such as a solid-state drive. The computer-readable storage medium can be a volatile or non-volatile storage medium, or can include both volatile and non-volatile types of storage media.
[0118] Those skilled in the art should understand that the embodiments of the present disclosure can be provided as a method, a system, or a computer program product. Therefore, the present disclosure can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present disclosure can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0119] The present disclosure is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the present disclosure. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable compliance detection devices of applications to generate a machine, such that the instructions executed by the processors of the computer or other programmable compliance detection devices of applications generate means for implementing the functions specified in the Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.
[0120] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable compliance detection device of an application to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in the Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.
[0121] These computer program instructions can also be loaded onto a computer or other programmable compliance detection device of an application, such that a series of operating steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in the Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.
[0122] In the description of this specification, the description with reference to terms such as "one embodiment / way", "some embodiments / ways", "example", "specific example", or "some examples", etc. means that the specific features, structures, or characteristics described in connection with the embodiment / way or example are included in at least one embodiment / way or example of the present disclosure. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment / way or example. Moreover, the specific features, structures, or characteristics described can be combined in a suitable manner in any one or more embodiments / ways or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments / ways or examples described in this specification and the features of different embodiments / ways or examples.
[0123] In addition, the terms "first" and "second" are for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include at least one such feature. In the description of the present disclosure, "a plurality of" means at least two, such as two, three, etc., unless otherwise specifically defined.
[0124] Those skilled in the art should understand that the above embodiments are merely for clearly illustrating the present disclosure and are not intended to limit the scope of the present disclosure. For those skilled in the art, other changes or modifications can be made based on the above disclosure, and these changes or modifications are still within the scope of the present disclosure.
[0125] It can be understood that before using the technical solutions disclosed in the embodiments of the present disclosure, the types, usage scopes, usage scenarios, etc. of the personal information involved in the present disclosure should be informed to the user and the user's authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.
[0126] For example, when receiving the user's active request, a prompt message is sent to the user to clearly prompt the user that the operation requested by the user will require obtaining and using the user's personal information. Thus, the user can autonomously choose whether to provide personal information to software or hardware such as an electronic device, an application program, a server, or a storage medium that executes the technical solution of the present disclosure according to the prompt message.
[0127] As an optional but non-limiting implementation manner, the manner of sending a prompt message to the user in response to receiving the user's active request may be, for example, in the form of a pop-up window, and the prompt message may be presented in text in the pop-up window. In addition, the pop-up window may also carry a selection control for the user to choose "agree" or "disagree" to provide personal information to the electronic device.
[0128] It can be understood that the above process of notifying and obtaining the user's authorization is merely illustrative and does not limit the implementation manner of the present disclosure. Other manners that meet relevant laws and regulations can also be applied to the implementation manner of the present disclosure.
[0129] At the same time, it can be understood that the data involved in the technical solution of the present disclosure (including but not limited to the data itself, the acquisition or use of the data) should comply with the requirements of the corresponding laws, regulations and related provisions.
Claims
1. A compliance detection method for an application, characterized in that, Including: Parsing the dependency information of the application to obtain a list of SDK information; Obtaining, from the list of SDK information, the call chain data of the application for describing the call relationships between methods; Parsing the call chain data to obtain the call chain of each method in the list of SDK information, so as to obtain a set of SDK call chains; Obtaining the mapping relationship between the target call chain and the SDK from the set of SDK call chains and using it as the call information of the target interface called by the target call chain; Detecting the matching degree between the call information of the target interface and the privacy permission statement of the application to obtain a matching degree detection result; And If the matching degree detection result is a first result indicating that the call information of the target interface does not match the privacy permission statement of the application, determining that the application is non-compliant.
2. The compliance detection method of the application according to claim 1, characterized in that, Parsing the dependency information of the application to obtain a list of SDK information, including: Parsing the dependency information of the application to extract third-party SDK metadata as the first data; If the dependency information of the application contains local dependencies, scanning the local project path to extract the SDK data integrated locally as the second data; and Performing data deduplication processing on the first data and the second data, and using the first data and the second data after data deduplication processing as the list of SDK information.
3. The compliance detection method of the application according to claim 2, characterized in that, Parsing the dependency information of the application to obtain a list of SDK information, further including: If the dependency information of the application does not contain local dependencies, skipping the scanning of the local project path and using the first data as the list of SDK information.
4. The compliance detection method for the application according to claim 1, characterized in that Obtaining the call chain data of the application from the list of SDK information, including: Traversing the file paths in the list of SDK information to find the binary executable files in the file paths; Obtaining the methods corresponding to the symbol information in the binary executable files; Establishing the corresponding relationship between the methods corresponding to the symbol information and the SDKs in the list of SDK information; and Based on the corresponding relationship, determining the static call path and the dynamic call path of the SDKs in the list of SDK information, and using the determined static call path and dynamic call path as the call chain data of the application.
5. The compliance detection method for the application according to claim 1, characterized in that, Parsing the call chain data to obtain the call chain of each method in the list of SDK information, so as to obtain a set of SDK call chains, including: Parsing the call chain data to obtain the call relationship between classes and methods; and Recursively traversing the call chains of the methods in each of the call relationships to obtain the set of SDK call chains.
6. The compliance detection method for the application according to claim 1, wherein Obtaining the mapping relationship between the target call chain and the SDK from the set of SDK call chains and using it as the call information of the target interface called by the target call chain, including: Determining the class and method corresponding to the target interface; Based on the class and method corresponding to the target interface, filtering out the target call chain in the set of SDK call chains; Splitting the individual methods in the target call chain as target methods; Querying the SDK to which the target method belongs; If the SDK to which the target method belongs is queried, determining the queried SDK as the target SDK; and Generate the mapping relationship between the target call chain and the SDK corresponding to the same target method as the call information of the target interface.
7. The compliance detection method for the application according to claim 1, characterized in that, Detect the matching degree between the call information of the target interface and the privacy permission statement of the application to obtain a matching degree detection result, including: When the target interface is a privacy interface, if any SDK in the call information of the privacy interface is not in the privacy permission statement of the application, determine that the call information of the target interface does not match the privacy permission statement of the application, and use the first result as the matching degree detection result; or When the target interface is the privacy interface, if any SDK in the privacy permission statement of the application is not in the call information of the privacy interface, determine that the call information of the target interface does not match the privacy permission statement of the application, and use the first result as the matching degree detection result.
8. An electronic device, characterized in that, Including: A memory that stores execution instructions; And A processor that executes the execution instructions stored in the memory, so that the processor executes the compliance detection method of the application according to any one of claims 1 to 7.
9. A readable storage medium, characterized in that, The readable storage medium stores execution instructions, and when the execution instructions are executed by a processor, they are used to implement the compliance detection method of the application according to any one of claims 1 to 7.
10. A computer program product comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the compliance detection method of the application according to any one of claims 1 to 7.