Application detection method and device for intelligent measurement terminal and computer equipment

Through the combination of autoencoder and normal distribution function, the accuracy problem of abnormal detection of intelligent measurement terminals is solved, adaptive recognition of unknown types and update of known types is realized, and detection accuracy is improved.

CN120429798AActive Publication Date: 2025-08-05GUANGZHOU POWER SUPPLY BUREAU GUANGDONG POWER GRID CO LTD +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510918901.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-04
Publication Date
2025-08-05
Estimated Expiration
2045-07-04

AI Technical Summary

Technical Problem

It is difficult for the prior art to accurately identify whether an abnormality occurs in the application of intelligent measurement terminals, mainly due to the short installation time and limited abnormal behavior data, resulting in inaccurate detection and identification models.

Method used

By obtaining the autoencoder and normal distribution functions of multiple application types, using the sample interface call sequence to train the autoencoder, constructing a normal distribution function, combining the actual call sequence features for detection probability calculation, and judging the type of the target application.

Benefits of technology

It improves the accuracy of detection of abnormal behaviors of intelligent measurement terminal applications, reduces the need for training data, can adaptively identify unknown types and update known types, and is suitable for application detection of intelligent measurement terminals.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120429798A_ABST
    Figure CN120429798A_ABST
Patent Text Reader

Abstract

The invention relates to an application detection method and device for an intelligent measurement terminal and computer equipment, relates to the technical field of power grids, and can improve the detection accuracy of application abnormal behaviors of the intelligent measurement terminal. The method comprises the following steps: acquiring self-encoders corresponding to a plurality of application types respectively; for each application type, inputting an actual interface calling sequence of a to-be-detected target application to a platform interface in the intelligent measurement terminal into an auto-encoder corresponding to the application type to obtain an actual calling sequence feature output by the auto-encoder, determining a detection probability that the target application belongs to the application type according to the actual call sequence characteristics and a normal distribution function corresponding to the auto-encoder; and determining an application type detection result of the target application according to each detection probability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of power grid technology, and in particular to an application detection method, device, computer equipment, computer-readable storage medium, and computer program product for an intelligent measurement terminal. Background Art

[0002] As a key component of the power grid, smart measurement terminals serve as a bridge between master stations and metering equipment, providing solid support for the accurate collection of comprehensive grid data and forming the core of the power grid measurement system. By installing various application software, smart measurement terminals can flexibly incorporate various required functions. However, this flexible application software installation also introduces potential security risks.

[0003] In related technologies, corresponding application detection and identification models can be established based on a large amount of application behavior anomaly data. However, currently, smart measurement terminals are only used for a short time, and the abnormal behavior data of applications installed on smart measurement terminals is relatively limited. Therefore, the detection and identification models obtained through the above methods are difficult to accurately and effectively identify whether the applications on smart measurement terminals are abnormal. Summary of the Invention

[0004] Based on this, it is necessary to provide an application detection method, device, computer equipment, computer-readable storage medium and computer program product for intelligent measurement terminals to address the above technical problems.

[0005] In a first aspect, the present application provides an application detection method for a smart measurement terminal, comprising:

[0006] Obtaining an autoencoder corresponding to each of a plurality of application types; the autoencoder is trained based on a sample interface call sequence of a platform interface by sample applications under the application type; the plurality of autoencoders respectively having a corresponding normal distribution function, the normal distribution function being determined based on sample call sequence features corresponding to each of the plurality of sample interface call sequences of the same application type;

[0007] For each application type, the actual interface call sequence of the target application to be detected in the intelligent measurement terminal to the platform interface is input into the autoencoder corresponding to the application type, the actual call sequence feature output by the autoencoder is obtained, and the detection probability of the target application belonging to the application type is determined based on the actual call sequence feature and the normal distribution function corresponding to the autoencoder;

[0008] An application type detection result of the target application is determined according to each of the detection probabilities.

[0009] In one embodiment, the autoencoder and normal distribution function corresponding to each application type are obtained by the following steps:

[0010] Running a sample application of the application type and determining a calling sequence of the platform interface during the running of the sample application;

[0011] Determining a sample interface calling sequence of the application type according to the interface code corresponding to the called interface in the calling sequence;

[0012] Training an initial autoencoder according to the sample interface call sequence, and upon completion of the training, obtaining sample call sequence features output by the trained autoencoder for each sample interface call sequence, and determining a mean and variance corresponding to each sample call sequence feature;

[0013] Determine a normal distribution function corresponding to the autoencoder based on the mean and variance.

[0014] In one embodiment, determining the application type detection result of the target application according to each detection probability includes:

[0015] determining a maximum probability among the detection probabilities;

[0016] If the maximum probability is greater than a preset threshold of the detection application type corresponding to the maximum probability, the detection application type is used as the application type detection result of the target application;

[0017] If the maximum probability is less than or equal to a preset threshold, it is determined that the application type detection result of the target application is an unknown application type.

[0018] In one embodiment, the preset threshold is determined by the following steps:

[0019] Obtaining a preset confidence level, and determining a quantile of a multidimensional chi-square distribution at the confidence level; the number of dimensions of the multidimensional chi-square distribution is determined according to the number of dimensions of the sample call sequence feature;

[0020] Determining a target calling sequence feature from a plurality of the sample calling sequence features; matching the corresponding modulus square of the target calling sequence feature with the value of the quantile;

[0021] Determining a probability corresponding to the target call sequence feature according to the target call sequence feature and the normal distribution function, and using the probability as a preset threshold;

[0022] or,

[0023] generating a plurality of first random vectors that obey the normal distribution function, and calculating an occurrence probability of each of the plurality of first random vectors;

[0024] Arrange the plurality of occurrence probabilities in descending order, and determine a target order according to a preset confidence level, wherein the target order is a maximum integer that does not exceed the confidence level;

[0025] The occurrence probability corresponding to the target sequence is determined in the descending order results as a preset threshold.

[0026] In one embodiment, if the maximum probability is less than or equal to a preset threshold, after determining that the detection result of the target application is an unknown application type, the method further includes:

[0027] Obtaining a new application type according to the type labeling result of the target application under the unknown application type;

[0028] Determine the number of sequences of the actual interface call sequences corresponding to the new application type. When the number of sequences reaches a quantity threshold, train the corresponding autoencoder according to each actual interface call sequence corresponding to the new application type to obtain the autoencoder and normal distribution function corresponding to the new application type.

[0029] In one embodiment, if the maximum probability is greater than a preset threshold of the detection application type corresponding to the maximum probability, then after taking the detection application type as the detection result of the target application, the method further includes:

[0030] According to the actual interface call sequence corresponding to the target application, a sample interface call sequence newly added to the detection application type is obtained;

[0031] generating a plurality of second random vectors that obey a normal distribution function corresponding to the detection application type, and decoding the plurality of second random vectors according to a decoder corresponding to an autoencoder of the detection application type to obtain a plurality of pseudo-coding sequences;

[0032] A new training set is obtained according to the multiple pseudo-coding sequences and the newly added sample interface calling sequence, and the autoencoder and normal distribution function for detecting the application type are updated according to the new training set.

[0033] In a second aspect, the present application further provides an application detection device for an intelligent measurement terminal, comprising:

[0034] An autoencoder acquisition module is configured to acquire autoencoders corresponding to respective application types; the autoencoders are trained based on sample interface call sequences of platform interfaces by sample applications of the application types; the plurality of autoencoders each have a corresponding normal distribution function, the normal distribution function being determined based on sample call sequence features corresponding to respective sample interface call sequences of the same application type;

[0035] a detection probability determination module, configured to, for each application type, input an actual interface call sequence of the target application to be detected in the intelligent measurement terminal to the platform interface into an autoencoder corresponding to the application type, obtain actual call sequence features output by the autoencoder, and determine a detection probability that the target application belongs to the application type based on the actual call sequence features and a normal distribution function corresponding to the autoencoder;

[0036] The detection result acquisition module is used to determine the application type detection result of the target application according to each of the detection probabilities.

[0037] In a third aspect, the present application further provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0038] Obtaining an autoencoder corresponding to each of a plurality of application types; the autoencoder is trained based on a sample interface call sequence of a platform interface by sample applications under the application type; the plurality of autoencoders respectively having a corresponding normal distribution function, the normal distribution function being determined based on sample call sequence features corresponding to each of the plurality of sample interface call sequences of the same application type;

[0039] For each application type, the actual interface call sequence of the target application to be detected in the intelligent measurement terminal to the platform interface is input into the autoencoder corresponding to the application type, the actual call sequence feature output by the autoencoder is obtained, and the detection probability of the target application belonging to the application type is determined based on the actual call sequence feature and the normal distribution function corresponding to the autoencoder;

[0040] An application type detection result of the target application is determined according to each of the detection probabilities.

[0041] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the following steps are implemented:

[0042] Obtaining an autoencoder corresponding to each of a plurality of application types; the autoencoder is trained based on a sample interface call sequence of a platform interface by sample applications under the application type; the plurality of autoencoders respectively having a corresponding normal distribution function, the normal distribution function being determined based on sample call sequence features corresponding to each of the plurality of sample interface call sequences of the same application type;

[0043] For each application type, the actual interface call sequence of the target application to be detected in the intelligent measurement terminal to the platform interface is input into the autoencoder corresponding to the application type, the actual call sequence feature output by the autoencoder is obtained, and the detection probability of the target application belonging to the application type is determined based on the actual call sequence feature and the normal distribution function corresponding to the autoencoder;

[0044] An application type detection result of the target application is determined according to each of the detection probabilities.

[0045] In a fifth aspect, the present application further provides a computer program product, comprising a computer program, which, when executed by a processor, implements the following steps:

[0046] Obtaining an autoencoder corresponding to each of a plurality of application types; the autoencoder is trained based on a sample interface call sequence of a platform interface by sample applications under the application type; the plurality of autoencoders respectively having a corresponding normal distribution function, the normal distribution function being determined based on sample call sequence features corresponding to each of the plurality of sample interface call sequences of the same application type;

[0047] For each application type, the actual interface call sequence of the target application to be detected in the intelligent measurement terminal to the platform interface is input into the autoencoder corresponding to the application type, the actual call sequence feature output by the autoencoder is obtained, and the detection probability of the target application belonging to the application type is determined based on the actual call sequence feature and the normal distribution function corresponding to the autoencoder;

[0048] An application type detection result of the target application is determined according to each of the detection probabilities.

[0049] The above-mentioned application detection method, device, computer equipment, computer-readable storage medium and computer program product for intelligent measurement terminals can obtain autoencoders corresponding to multiple application types, wherein the autoencoders are trained based on the sample interface call sequences of the sample applications under the application type to the platform interface, and the multiple autoencoders respectively have corresponding normal distribution functions, which are determined based on the sample call sequence characteristics corresponding to the multiple sample interface call sequences of the same application type; and then, for each application type, the actual interface call sequence of the target application to be detected in the intelligent measurement terminal to the platform interface can be input into the autoencoder corresponding to the application type to obtain the actual call sequence characteristics output by the autoencoder, and the detection probability that the target application belongs to the application type can be determined based on the actual call sequence characteristics and the normal distribution function corresponding to the autoencoder; then, the application type detection result of the target application can be determined based on each detection probability. In this embodiment, by using sample applications under the application type to train multiple sample interface call sequences of the platform interface, the sample call sequence features output by the autoencoder are obtained. A normal distribution function can be constructed based on the sample call sequence features. Therefore, the continuity of the normal distribution can be used to infer the overall distribution characteristics of the call sequence features under a certain application type from the limited sample call sequence features, and the probability of various uncovered interface call behaviors can be estimated. When detecting a new application, by combining the actual call sequence features with the inferred call sequence feature distribution (i.e., the normal distribution function), it is possible to more accurately determine whether the call sequence features meet the characteristics of the interface call sequence of an application under a certain application type, thereby effectively improving the accuracy of detecting abnormal behavior of the smart measurement terminal application. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments of the present application or related technical descriptions. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying any creative work.

[0051] Figure 1 1 is a flow chart of an application detection method for an intelligent measurement terminal according to an embodiment;

[0052] Figure 2 1 is a flow chart of another application detection method for an intelligent measurement terminal according to an embodiment;

[0053] Figure 3 is a structural block diagram of an application detection device for an intelligent measurement terminal in one embodiment;

[0054] Figure 4is a diagram of the internal structure of a computer device in one embodiment;

[0055] Figure 5 FIG. 1 is a diagram showing the internal structure of another computer device in one embodiment. DETAILED DESCRIPTION

[0056] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0057] In order to enable those skilled in the art to better understand this application, the relevant technologies are first introduced below.

[0058] As a key component of the power grid, the intelligent measurement terminal serves as a bridge between the master station and metering equipment, providing solid support for the accurate collection of comprehensive grid data and forming the core of the power grid measurement system. In some examples, the intelligent measurement terminal is an integrated, intelligent power device capable of collecting real-time grid electrical parameters such as voltage, current, power factor, frequency, and harmonics, and uploading this data to a grid dispatch center or cloud platform via a communication interface. It can also process and analyze the collected data, providing assessment, prediction, and alarm functions for the grid's operating status. Furthermore, the intelligent measurement terminal has remote control capabilities, receiving instructions from higher-level systems to enable remote control and optimization of grid equipment. This functionality makes grid management more convenient and efficient, improving grid security and reliability.

[0059] As power grids continue to evolve toward digitalization and intelligence, smart metering terminals must possess greater flexibility to accommodate and support diverse functional requirements. To address this challenge, a combination of software platforms and applications can be adopted. By installing different applications on smart metering terminals, these terminals can be flexibly equipped with the required functionality, offering an effective strategy. However, flexible application installation also presents potential security risks. To ensure safe and stable grid operation, applications installed on smart metering terminals must undergo thorough testing and verification (e.g., before deployment and / or after deployment).

[0060] In related technologies, corresponding application detection and identification models can be established based on large amounts of data on abnormal application behavior. However, as a newly developed technology, smart measurement terminals use an operating environment that is significantly different from general-purpose operating systems. This makes it difficult to directly apply more mature tools, databases, and methods on common platforms to smart measurement terminal detection. New detection and identification models are needed. Furthermore, smart measurement terminals are currently in use for a short time, and the abnormal behavior data of applications installed on them is limited and incomplete. Therefore, the detection and identification models built using related technologies that rely on large amounts of abnormal data are not accurate, making it difficult to accurately and effectively identify whether an application on a smart measurement terminal has experienced an anomaly.

[0061] Based on this, it is necessary to provide an application detection method, device, computer equipment, computer-readable storage medium and computer program product for intelligent measurement terminals to address the above technical problems.

[0062] In one embodiment, Figure 1 As shown, a method for detecting an application of an intelligent measurement terminal is provided. This embodiment uses the method applied to a terminal as an example. It is understood that the method can also be applied to a server, or to a system including a terminal and a server, and implemented through interaction between the terminal and the server. In this embodiment, the method includes the following steps:

[0063] S101, obtain an autoencoder corresponding to each of the multiple application types; the autoencoder is trained based on a sample interface call sequence of the platform interface according to the sample application under the application type; the multiple autoencoders respectively have a corresponding normal distribution function, and the normal distribution function is determined based on the sample call sequence characteristics corresponding to each of the multiple sample interface call sequences of the same application type.

[0064] An autoencoder (AE) is a neural network that learns a compressed representation of data and attempts to reconstruct the original input data. An autoencoder primarily consists of an encoder, an encoding space, and a decoder. The encoder maps the input data to a low-dimensional space, generating latent variables corresponding to the input data. The decoder attempts to restore the latent variables in the low-dimensional space to the original input data. In some examples, autoencoders can be used for tasks such as data denoising, feature extraction, and data dimensionality reduction.

[0065] In a specific implementation, autoencoders corresponding to multiple application types can be pre-trained. Specifically, applications with pre-labeled types for training the initial model can be obtained. These applications are also called sample applications, and sample applications under each application type can be obtained. The multiple sample applications can include applications under each application type that needs to be identified. In some examples, the multiple sample applications can include normal applications and abnormal applications, and the abnormal applications can include abnormal applications of different abnormal types. After obtaining the multiple sample applications, the multiple sample applications can be run in a sandbox. For example, each sample application can be run in the sandbox.

[0066] Specifically, malicious code contained in an application is a software program designed to damage, interfere with, or harm a computer system. Malicious code poses a serious threat to the operational safety of the power grid through one or more methods, including but not limited to attacking computer systems and disrupting system functions. Therefore, malicious code detection is a crucial step in pre-launch inspection of smart metering terminal applications. Related technologies can detect malicious code through signature detection, heuristic detection, behavioral analysis, and cloud-based detection. However, in practice, these methods have failed to effectively adapt to the characteristics of smart metering terminals.

[0067] In this regard, the inventors discovered through practice that, as a dedicated device in the power grid system, the application operating environment of the smart measurement terminal has its own particularity. Specifically, the communication between the application of the smart measurement terminal and the master station and metering equipment, as well as the data exchange between different applications on the smart measurement terminal are all completed through the platform interface (Application Programming Interface, API) provided by the software platform. Therefore, the interface call sequence of the sample application can be obtained. Among them, the interface call sequence is also called the API call sequence. The interface call sequence can be composed of the interface codes of multiple platform interfaces. The order of the multiple interface codes in the sequence is determined according to the order in which the platform interfaces are called. For the sake of distinction, the interface call sequence of the sample application can be referred to as the sample interface call sequence.

[0068] Furthermore, for each application type, the sample interface call sequences obtained after running all sample application programs of the application type can constitute a training data set of the application type, which is used to train the autoencoder corresponding to the application type.

[0069] When training the autoencoder for each application type, the sample interface call sequence can be input into the autoencoder, and the autoencoder performs feature extraction on the input sample interface call sequence (that is, obtains the latent variables of the sample interface call sequence) to obtain the corresponding sample call sequence features. Then, the sample call sequence features corresponding to the multiple sample interface call sequences under the application type can be combined to perform statistics to obtain a normal distribution function (also called a Gaussian distribution function) that matches the distribution of the multiple sample call sequence features. The normal distribution function is used as the normal distribution function corresponding to the autoencoder. It can be understood that by constructing a corresponding normal distribution function for the sample call sequence features, the continuity of the normal distribution can be used to infer the overall distribution characteristics of the call sequence features under a certain application type from the limited sample call sequence features, thereby being able to make a probability estimate for new data that is not covered. When detecting a new application, this application can more accurately judge whether the call sequence features meet the characteristics of the interface call sequence of an application under a certain application type by comparing the call sequence features with the inferred call sequence feature distribution range, thereby reducing the number of samples required to train the detection model and facilitating use in practice.

[0070] S102: For each application type, the actual interface call sequence of the target application to be detected in the intelligent measurement terminal to the platform interface is input into the autoencoder corresponding to the application type, and the actual call sequence features output by the autoencoder are obtained. Based on the actual call sequence features and the normal distribution function corresponding to the autoencoder, the detection probability of the target application belonging to the application type is determined.

[0071] In this step, the application to be detected for abnormal behavior corresponding to the smart measurement terminal can be called the target application. The target application can be an application to be put on the shelf or deployed to the smart measurement terminal, or it can be an application already installed in the smart measurement terminal. After determining the target application, the target application can be run, and the calls to the platform interface by the target application during operation can be recorded to obtain the interface call sequence corresponding to the target application. For ease of distinction, the interface call sequence is also called the actual interface call sequence. In some examples, when testing a new target application, the target application can be run in a sandbox, and the platform interfaces of the software platform called by the target application during operation can be recorded in sequence. The actual interface call sequence is generated based on the interface codes corresponding to each platform interface and the calling order of each platform interface.

[0072] The actual interface call sequence can then be input into the autoencoder corresponding to each application type. For each application type, the autoencoder can obtain the sequence features corresponding to the input actual interface call sequence, namely the actual call sequence features. In one example, the actual call sequence features can also be called the latent variable sequence. After the autoencoder outputs the actual call sequence features, the detection probability of the target application belonging to that application type can be determined based on the actual call sequence features and the normal distribution function corresponding to the autoencoder.

[0073] In one embodiment, the probability that the latent variable (interface call feature) at each moment in the latent variable sequence (i.e., the actual call sequence feature) belongs to different types can be calculated. For example, the latent variable at each moment in the latent variable sequence can be input into the normal distribution function corresponding to different types of applications. In the above equation, we can get the probability that the above latent variables belong to different types of applications.

[0074] S103: Determine an application type detection result of the target application according to each detection probability.

[0075] After obtaining the detection probabilities of the target application belonging to various application types, the detection probabilities can be compared to determine the application type detection result of the target application. For example, the application type detection result of the target application can be obtained based on the application type with the highest detection probability.

[0076] In the above-mentioned application detection method for the intelligent measurement terminal, an autoencoder corresponding to each of the multiple application types can be obtained, wherein the autoencoder is trained based on the sample interface call sequence of the sample application under the application type to the platform interface, and the multiple autoencoders respectively have corresponding normal distribution functions, which are determined based on the sample call sequence characteristics corresponding to the multiple sample interface call sequences of the same application type; and then for each application type, the actual interface call sequence of the target application to be detected in the intelligent measurement terminal to the platform interface can be input into the autoencoder corresponding to the application type to obtain the actual call sequence characteristics output by the autoencoder, and the detection probability that the target application belongs to the application type can be determined based on the actual call sequence characteristics and the normal distribution function corresponding to the autoencoder; then, the application type detection result of the target application can be determined based on each detection probability. In this embodiment, by using sample applications under the application type to train multiple sample interface call sequences of the platform interface, the sample call sequence features output by the autoencoder are obtained. A normal distribution function can be constructed based on the sample call sequence features. Therefore, the continuity of the normal distribution can be used to infer the overall distribution characteristics of the call sequence features under a certain application type from the limited sample call sequence features, and the probability of various uncovered interface call behaviors can be estimated. When detecting a new application, by combining the actual call sequence features with the inferred call sequence feature distribution (i.e., the normal distribution function), it is possible to more accurately determine whether the call sequence features meet the characteristics of the interface call sequence of an application under a certain application type, thereby effectively improving the accuracy of detecting abnormal behavior of the smart measurement terminal application.

[0077] In one embodiment, the autoencoder and normal distribution function corresponding to each application type can be obtained by the following steps:

[0078] Run a sample application under the application type and determine the calling sequence of the platform interface during the running of the sample application; determine the sample interface calling sequence of the application type based on the interface code corresponding to the called interface in the calling sequence; train an initial autoencoder based on the sample interface calling sequence, and when the training is completed, obtain the sample calling sequence features output by the trained autoencoder for each sample interface calling sequence, and determine the mean and variance corresponding to each sample calling sequence feature; determine the normal distribution function corresponding to the autoencoder based on the mean and variance.

[0079] Specifically, for each application type, you can run (or simulate running) a sample application under the application type in a sandbox environment to observe whether there are any abnormalities in the sample application's calls to the platform interface, so as to effectively identify and detect whether the application contains malicious code.

[0080] For each sample application, the platform interfaces of the software platform called during the application's runtime can be recorded in the order in which the platform interfaces are called, thereby obtaining the call sequence of the platform interfaces during the sample application's operation. Alternatively, a list of the smart measurement terminal software platform APIs can be created, and each API can be encoded. For example, the API can be one-hot encoded to obtain the interface code corresponding to each platform interface. Based on the interface code corresponding to each platform interface, the sample interface call sequence for the application type can then be determined.

[0081] After obtaining the sample interface call sequence, the initial autoencoder can be trained according to the sample interface call sequence. In some exemplary embodiments, the sample interface call sequence can be used to perform self-supervised training on the initial autoencoder, that is, the sample interface call sequence can be input into the autoencoder, and the encoder in the autoencoder extracts features of the sample interface call sequence to obtain corresponding sample call sequence features, and then the decoder in the autoencoder decodes the sample call sequence features to obtain a decoded interface call sequence, and adjusts the model parameters of the autoencoder according to the difference between the decoded interface call sequence and the sample interface call sequence, and repeats the above process until the training end condition is met.

[0082] When the training is completed, the sample call sequence features output by the trained autoencoder for each sample interface call sequence can be obtained, and the mean and variance of the output of the encoder in the autoencoder can be calculated, that is, the mean and variance corresponding to each sample call sequence feature can be determined, and then based on the mean and variance, the normal distribution function corresponding to the output latent variable of the corresponding application type encoder (that is, the sample call sequence feature) can be established and used as the normal distribution function corresponding to the corresponding application type autoencoder.

[0083] In some exemplary embodiments, the encoder of the autoencoder can be composed of two long short-term memory networks (LSTM) and one fully connected layer (FC) connected in sequence, and the decoder can be composed of one fully connected layer and two long short-term memory networks. After the training is completed, the mean and variance of the output (i.e., the sample call sequence features) obtained by the encoder for each API call sequence of the i-th application type can be calculated to determine the normal distribution function corresponding to the latent variable output by the encoder of the i-th application type. , in this normal distribution function, z is the latent variable output by the encoder, and are the mean and variance of the latent variable z output by the i-th application type encoder, and I is the identity matrix.

[0084] In some examples, in order to make the latent variable distribution of the autoencoder output as close as possible to the standard normal distribution, the following loss function can be used when training the autoencoder :

[0085]

[0086] Where k is the index of the input and output code vectors, j is the index of the component in the code vector, and i is the index of the application type. and represents the jth component of the kth input and output vectors in the training data for the i-th application type, and denote the jth component of the mean and variance vector of the i-th application type, respectively. The preset weight.

[0087] In this embodiment, an initial autoencoder is trained according to a sample interface call sequence. When the training is completed, the sample call sequence features output by the trained autoencoder for each sample interface call sequence are obtained, the mean and variance corresponding to each sample call sequence feature are determined, and the normal distribution function corresponding to the autoencoder is determined based on the mean and variance. The output latent variable of the encoder in the autoencoder can be modeled as a multidimensional normal distribution, which provides a reliable basis for determining whether a new type of data appears or determining the detection probability of the target application belonging to a known application type through the subsequent confidence interval of the multidimensional normal distribution.

[0088] In one embodiment, in step S103, determining the application type detection result of the target application according to each detection probability may include the following steps:

[0089] Determine the maximum probability among the detection probabilities; if the maximum probability is greater than the preset threshold of the detection application type corresponding to the maximum probability, then use the detected application type as the application type detection result of the target application; if the maximum probability is less than or equal to the preset threshold, then determine that the application type detection result of the target application is an unknown application type.

[0090] In one example, the detected application type includes a normal application or an abnormal application.

[0091] In practical applications, the detection probabilities may be compared, and the maximum probability may be determined. The application type corresponding to the maximum probability may be recorded. For ease of distinction, the application type corresponding to the maximum probability may be referred to as the detection application type.

[0092] The detection probabilities of different application types may have corresponding preset thresholds. If the maximum probability is greater than the preset threshold for the detection application type corresponding to the maximum probability, the detection application type corresponding to the maximum probability may be used as the application type detection result for the target application. If the maximum probability is less than or equal to the preset threshold, the application type detection result for the target application may be determined to be an unknown application type.

[0093] For example, the preset thresholds for application type A and application type B are a and b respectively. When the detection application type corresponding to the maximum probability is application type A, the maximum probability can be compared with the preset threshold a. When the detection application type corresponding to the maximum probability is application type B, the maximum probability can be compared with the preset threshold b.

[0094] In this embodiment, the detection probability that the target application belongs to a certain application type can be calculated based on the normal distribution function. When the maximum probability among multiple detection probabilities is less than or equal to a preset threshold, it can be automatically classified as an unknown application type. This allows new unknown types to be discovered quickly without preparing data of unknown types in advance, which is convenient for actual use.

[0095] In one embodiment, the preset threshold used in the above embodiment can be determined by the following method:

[0096] Obtain a preset confidence level and determine the quantile of the multidimensional chi-square distribution at the confidence level; the number of dimensions of the multidimensional chi-square distribution is determined according to the number of dimensions of the sample call sequence characteristics; determine the target call sequence characteristics from the sample call sequence characteristics; match the modulus square corresponding to the target call sequence characteristics with the quantile value; determine the probability corresponding to the target call sequence characteristics based on the target call sequence characteristics and the normal distribution function, and use the probability as a preset threshold.

[0097] Specifically, for each application type, the preset confidence level can be determined first. . Then we can calculate the N-dimensional chi-square distribution Quantile . If n independent random variables , ,…, All obey the standard normal distribution (also known as independent and identically distributed in the standard normal distribution), then the sum of the squares of the n random variables obeying the standard normal distribution constitutes a new random variable, whose distribution law is called the chi-square distribution. In this embodiment, N can be a hidden variable (i.e., the dimension of the sample call sequence feature). Subsequently, the target call sequence feature can be determined from the sample call sequence feature. For example, any dimension that makes the square of the modulus of , use it as the target call sequence feature, and calculate the output probability corresponding to the target call sequence feature based on the target call sequence feature and the normal distribution function corresponding to the autoencoder of this application type (such as the standard normal distribution) , which is used as the preset threshold.

[0098] In another embodiment, the preset threshold used in the above embodiment can also be determined by the following method 2:

[0099] Generate multiple first random vectors that obey a normal distribution function, and calculate the probability of occurrence of each of the multiple first random vectors; arrange the multiple occurrence probabilities in descending order, and determine a target order based on a preset confidence level, where the target order is a maximum integer that does not exceed the confidence level; and determine the probability of occurrence corresponding to the target order in the descending order result as a preset threshold.

[0100] In practical applications, for each application type, we can first determine the preset confidence level. On the other hand, it can generate a normal distribution function that obeys the application type M (M ≥ 2) first random vectors, and calculate the probability of occurrence of the M first random vectors Then, sort the multiple occurrence probabilities from large to small, and The probability of occurrence of is determined as a preset threshold, where Represents the largest integer not exceeding x.

[0101] In this embodiment, determining the preset threshold by using the above-mentioned method 1 or method can make the setting of the preset threshold more consistent with the intrinsic distribution law of the call sequence characteristics of each application type sample, provide a more reasonable basis for accurately judging whether the target application is abnormal, and improve the accuracy and reliability of detection.

[0102] In one embodiment, if the maximum probability is less than or equal to a preset threshold, after determining that the detection result of the target application is an unknown application type, the following steps may be further included:

[0103] A new application type is obtained based on the type labeling results of the target application under the unknown application type; the number of sequences of actual interface call sequences corresponding to the new application type is determined, and when the number of sequences reaches a quantity threshold, the corresponding autoencoder is trained according to the actual interface call sequences corresponding to the new application type to obtain the autoencoder and normal distribution function corresponding to the new application type.

[0104] In actual applications, as the platform usage time increases, new types of abnormal application behaviors may appear. The model built using old data may find it difficult to accurately identify the corresponding abnormal situations. In this regard, timely adjustments can be made to adapt to new situations.

[0105] In this embodiment, if the target application belongs to an unknown application type, it can be manually labeled and classified into a known application type or a new application type based on the type labeling results. When the target application is classified into a new application type, the actual interface call sequence corresponding to the target application can be used as training data for the new application type, and the number of actual interface call sequences corresponding to the new application type can be counted to determine the number of actual interface call sequences classified into the new application type.

[0106] When the number of sequences reaches the threshold, the corresponding autoencoder can be trained based on the actual interface call sequences corresponding to the new application type to obtain the autoencoder and normal distribution function corresponding to the new application type. Regarding the steps for training the autoencoder corresponding to the new application type and obtaining its normal distribution function, refer to the aforementioned related embodiments, and the processing process is similar and is not repeated here.

[0107] In some related technologies, when detecting abnormal application behavior, in order to deal with problems such as dimensionality disasters and rapid changes in data distribution caused by application version updates, application detection is performed based on semantic feature enhancement methods and incremental learning. However, this method cannot automatically identify new types. At the same time, during incremental learning, a calibration set consisting of old data needs to be saved, which requires additional storage space.

[0108] In this regard, in this embodiment, based on the discovery of new unknown types according to the normal distribution function, as the number of sequences of the actual interface call sequence of the new mode increases, the actual interface call sequence corresponding to the new application type is obtained according to the type labeling result, and when the number of sequences reaches a quantity threshold, the autoencoder and normal distribution function corresponding to the new application type are obtained. New autoencoders can be adaptively added to make the application type detection results more and more accurate. It is particularly suitable for new platforms such as smart measurement terminals that do not have sufficient training data, and there is no need to store old data. It can not only be used to detect abnormal behavior of applications in smart measurement terminals, but can also be widely used in other occasions that require adjusting models according to new data, and has high versatility.

[0109] In one embodiment, if the maximum probability is greater than a preset threshold of the detection application type corresponding to the maximum probability, after taking the detection application type as the detection result of the target application, the following steps may be further included:

[0110] According to the actual interface call sequence corresponding to the target application, a new sample interface call sequence of the detection application type is obtained; a plurality of second random vectors that obey the normal distribution function corresponding to the detection application type are generated, and the plurality of second random vectors are decoded according to the decoder corresponding to the autoencoder of the detection application type to obtain a plurality of pseudo-coding sequences; a new training set is obtained according to the plurality of pseudo-coding sequences and the new sample interface call sequence, and the autoencoder and normal distribution function of the detection application type are updated according to the new training set.

[0111] As the platform usage time increases, the interface call sequences under the original known application types will increase accordingly. For example, the interface call sequences of normal applications and abnormal applications will increase. In this regard, the existing autoencoders can be adjusted in time to adapt to the new situation.

[0112] In this embodiment, if the actual interface call sequence is determined to be an interface call sequence of a known application type according to a preset threshold or manually determined, then on the one hand, a normal distribution function can be generated. The Y second random vectors are generated, with the same number of dimensions as the sample call sequence features. These Y second random vectors can then be passed through the decoder in the autoencoder to obtain a pseudo-coding sequence generated by the decoder. Multiple pseudo-coding sequences and the newly added sample interface call sequences for this application type can then be combined to form a new training set. This new training set is used to update the autoencoder and normal distribution function for detecting application types.

[0113] In this embodiment, on the one hand, the original autoencoder can be adaptively adjusted as the data increases, so that the model detection results become more and more accurate, effectively meeting the application detection needs of new platforms such as smart measurement terminals that do not have sufficient training data. On the other hand, by sampling the normal distribution function, the probability distribution model of the sample call sequence characteristics can be used to generate random latent variables, and pseudo training data can be generated through the decoder. These are combined with new data (i.e., the actual interface call sequence under the corresponding application type) to train the known type of autoencoder and normal distribution function. Therefore, there is no need to store old data when updating the autoencoder, and the number of new and old training data can be effectively balanced.

[0114] In order to enable those skilled in the art to better understand the above steps, the embodiment of the present application is illustrated below by using an example, but it should be understood that the embodiment of the present application is not limited to this.

[0115] like Figure 2 As shown, this embodiment may include the following steps:

[0116] S201: Create a list of APIs for the intelligent measurement terminal software platform and encode each API.

[0117] S202: Run an application program for training an initial model with a marked type in a sandbox, and record the codes of the software platform APIs called when the application program is running in sequence to form an API call sequence.

[0118] S203: For each application with a labeled type, use its API call sequence to train the autoencoder corresponding to the type, calculate the mean and variance of the encoder output in the autoencoder, and establish a normal distribution function corresponding to the latent variable of the encoder output of the above type.

[0119] S204 , when testing a new application, the application is run in a sandbox, and the codes of the software platform APIs called when the application is running are recorded in sequence to form an API call sequence.

[0120] S205 , input the above API call sequence into the autoencoder corresponding to each type to obtain the latent variable sequence output by the encoder.

[0121] S206 , calculating the probability that the latent variable at each moment in the latent variable sequence belongs to a different type according to the normal distribution function corresponding to each type.

[0122] S207: Select the maximum probability among the above probabilities and record its corresponding type. If the maximum probability is greater than a preset threshold, the current application belongs to the above type. Otherwise, it belongs to an unknown type and is manually labeled to be classified as a known type or a new type.

[0123] S208, when the number of new data of a certain type reaches a preset value, for the new type, the same method as steps S202 and S203 is used to establish the autoencoder and normal distribution function corresponding to the above new type. For the old type, the autoencoder is retrained and the corresponding normal distribution function is calculated.

[0124] In response to the problems in the related art of detecting abnormal behavior of applications in smart measurement terminals, such as a small amount of abnormal data, an inaccurate initial model, and the need to update the model over time, this embodiment uses an autoencoder to process the API call sequence of the application and models its latent variables as a normal distribution function. The normal distribution function is used to initially mark whether the new data is abnormal, and then the new data and the training data generated by the normal distribution function are used to train a new autoencoder or adjust the parameters of the old autoencoder. The present invention can adjust the parameters of the model or add new types as the data increases, without the need to store old data, and can also well balance the number of different types of data. It can not only be used for abnormal behavior of applications in smart measurement terminals, but can also be widely used in other occasions where the model needs to be adjusted according to new data.

[0125] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.

[0126] Based on the same inventive concept, embodiments of the present application also provide an application detection device for smart measurement terminals, which is used to implement the aforementioned application detection method for smart measurement terminals. The solution provided by this device is similar to the solution described in the aforementioned method. Therefore, the specific limitations of one or more embodiments of the application detection device for smart measurement terminals provided below can be found in the aforementioned limitations of the application detection method for smart measurement terminals, and will not be further elaborated here.

[0127] In an exemplary embodiment, Figure 3 As shown, an application detection device for an intelligent measurement terminal is provided, comprising:

[0128] An autoencoder acquisition module 301 is configured to acquire autoencoders corresponding to multiple application types; the autoencoders are trained based on sample interface call sequences of platform interfaces from sample applications of the application types; the multiple autoencoders each have a corresponding normal distribution function, and the normal distribution function is determined based on sample call sequence features corresponding to the multiple sample interface call sequences of the same application type;

[0129] The detection probability determination module 302 is configured to, for each application type, input the actual interface call sequence of the target application to be detected in the intelligent measurement terminal to the platform interface into the autoencoder corresponding to the application type, obtain the actual call sequence features output by the autoencoder, and determine the detection probability that the target application belongs to the application type based on the actual call sequence features and the normal distribution function corresponding to the autoencoder;

[0130] The detection result acquisition module 303 is configured to determine an application type detection result of the target application according to each of the detection probabilities.

[0131] In one embodiment, the apparatus further comprises a model training module, wherein the model training module is configured to:

[0132] Running a sample application of the application type and determining a calling sequence of the platform interface during the running of the sample application;

[0133] Determining a sample interface calling sequence of the application type according to the interface code corresponding to the called interface in the calling sequence;

[0134] Training an initial autoencoder according to the sample interface call sequence, and upon completion of the training, obtaining sample call sequence features output by the trained autoencoder for each sample interface call sequence, and determining a mean and variance corresponding to each sample call sequence feature;

[0135] Determine a normal distribution function corresponding to the autoencoder based on the mean and variance.

[0136] In one embodiment, the detection result acquisition module 303 is used to:

[0137] determining a maximum probability among the detection probabilities;

[0138] If the maximum probability is greater than a preset threshold of the detection application type corresponding to the maximum probability, the detection application type is used as the application type detection result of the target application;

[0139] If the maximum probability is less than or equal to a preset threshold, it is determined that the application type detection result of the target application is an unknown application type.

[0140] In one embodiment, the detection result acquisition module 303 is used to:

[0141] Obtaining a preset confidence level, and determining a quantile of a multidimensional chi-square distribution at the confidence level; the number of dimensions of the multidimensional chi-square distribution is determined according to the number of dimensions of the sample call sequence feature;

[0142] Determining a target calling sequence feature from a plurality of the sample calling sequence features; matching the corresponding modulus square of the target calling sequence feature with the value of the quantile;

[0143] Determining a probability corresponding to the target call sequence feature according to the target call sequence feature and the normal distribution function, and using the probability as a preset threshold;

[0144] or,

[0145] generating a plurality of first random vectors that obey the normal distribution function, and calculating an occurrence probability of each of the plurality of first random vectors;

[0146] Arrange the plurality of occurrence probabilities in descending order, and determine a target order according to a preset confidence level, wherein the target order is a maximum integer that does not exceed the confidence level;

[0147] The occurrence probability corresponding to the target sequence is determined in the descending order results as a preset threshold.

[0148] In one embodiment, the apparatus further comprises a model updating module, wherein the model updating module is configured to:

[0149] Obtaining a new application type according to the type labeling result of the target application under the unknown application type;

[0150] Determine the number of sequences of the actual interface call sequences corresponding to the new application type. When the number of sequences reaches a quantity threshold, train the corresponding autoencoder according to each actual interface call sequence corresponding to the new application type to obtain the autoencoder and normal distribution function corresponding to the new application type.

[0151] In one embodiment, the apparatus further comprises a model updating module, wherein the model updating module is configured to:

[0152] According to the actual interface call sequence corresponding to the target application, a sample interface call sequence newly added to the detection application type is obtained;

[0153] generating a plurality of second random vectors that obey a normal distribution function corresponding to the detection application type, and decoding the plurality of second random vectors according to a decoder corresponding to an autoencoder of the detection application type to obtain a plurality of pseudo-coding sequences;

[0154] A new training set is obtained according to the multiple pseudo-coding sequences and the newly added sample interface calling sequence, and the autoencoder and normal distribution function for detecting the application type are updated according to the new training set.

[0155] In one embodiment, the actual call sequence characteristics include interface call characteristics corresponding to multiple moments during the running process of the target application;

[0156] The detection probability determination module 302 is configured to:

[0157] determining, based on a normal distribution function corresponding to the autoencoder and each interface call feature in the actual call sequence feature, an initial probability that the target application belongs to the application type at each moment;

[0158] A detection probability that the target application belongs to the application type is determined based on the multiple initial probabilities.

[0159] Each module in the aforementioned application detection device for intelligent measurement terminals can be implemented in whole or in part through software, hardware, or a combination thereof. Each module can be embedded in or independent of a processor in a computer device in hardware form, or can be stored in a computer device memory in software form, so that the processor can call and execute the corresponding operations of each module.

[0160] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as shown in FIG. Figure 4 As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O) and a communication interface. The processor, memory and input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store interface call data. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, an application detection method for an intelligent measurement terminal is implemented.

[0161] In an exemplary embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as shown in FIG. Figure 5As shown. The computer device includes a processor, memory, an input / output interface, a communication interface, a display unit, and an input device. The processor, memory, and input / output interface are connected via a system bus, and the communication interface, display unit, and input device are connected to the system bus via the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals via wired or wireless means, and the wireless means can be implemented via Wi-Fi, a mobile cellular network, near-field communication (NFC), or other technologies. When executed by the processor, the computer program implements an application detection method for a smart measurement terminal. The display unit of the computer device is used to form a visually visible image, and can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or a button, trackball or touchpad set on the computer device casing, or an external keyboard, touchpad or mouse.

[0162] Those skilled in the art will understand that Figure 4 and Figure 5 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0163] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, and the processor implements the steps in the above method embodiments when executing the computer program.

[0164] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.

[0165] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.

[0166] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.

[0167] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. In particular, any reference to memory, database, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the various embodiments provided herein may be, but are not limited to, general-purpose processors, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), programmable logic devices (PLDs), quantum computing-based data processing logic devices, artificial intelligence (AI) processors, and the like.

[0168] The technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0169] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.

Claims

1. An application detection method for an intelligent measurement terminal, characterized in that: The method comprises: Obtaining an autoencoder corresponding to each of a plurality of application types; the autoencoder is trained based on a sample interface call sequence of a platform interface by sample applications under the application type; the plurality of autoencoders respectively having a corresponding normal distribution function, the normal distribution function being determined based on sample call sequence features corresponding to each of the plurality of sample interface call sequences of the same application type; For each application type, the actual interface call sequence of the target application to be detected in the intelligent measurement terminal to the platform interface is input into the autoencoder corresponding to the application type, the actual call sequence feature output by the autoencoder is obtained, and the detection probability of the target application belonging to the application type is determined based on the actual call sequence feature and the normal distribution function corresponding to the autoencoder; An application type detection result of the target application is determined according to each of the detection probabilities.

2. The method according to claim 1, characterized in that The autoencoder and normal distribution function corresponding to each application type are obtained by the following steps: Running a sample application of the application type and determining a calling sequence of the platform interface during the running of the sample application; Determining a sample interface calling sequence of the application type according to the interface code corresponding to the called interface in the calling sequence; Training an initial autoencoder according to the sample interface call sequence, and upon completion of the training, obtaining sample call sequence features output by the trained autoencoder for each sample interface call sequence, and determining a mean and variance corresponding to each sample call sequence feature; Determine a normal distribution function corresponding to the autoencoder based on the mean and variance.

3. The method according to claim 1, characterized in that The determining of the application type detection result of the target application according to each of the detection probabilities includes: determining a maximum probability among the detection probabilities; If the maximum probability is greater than a preset threshold of the detection application type corresponding to the maximum probability, the detection application type is used as the application type detection result of the target application; If the maximum probability is less than or equal to a preset threshold, it is determined that the application type detection result of the target application is an unknown application type.

4. The method according to claim 3, characterized in that The preset threshold is determined by the following steps: Obtaining a preset confidence level, and determining a quantile of a multidimensional chi-square distribution at the confidence level; the number of dimensions of the multidimensional chi-square distribution is determined according to the number of dimensions of the sample call sequence feature; Determining a target calling sequence feature from a plurality of the sample calling sequence features; matching the corresponding modulus square of the target calling sequence feature with the value of the quantile; Determining a probability corresponding to the target call sequence feature according to the target call sequence feature and the normal distribution function, and using the probability as a preset threshold; or, generating a plurality of first random vectors that obey the normal distribution function, and calculating an occurrence probability of each of the plurality of first random vectors; Arrange the plurality of occurrence probabilities in descending order, and determine a target order according to a preset confidence level, wherein the target order is a maximum integer that does not exceed the confidence level; The occurrence probability corresponding to the target sequence is determined in the descending order results as a preset threshold.

5. The method according to claim 3, characterized in that If the maximum probability is less than or equal to a preset threshold, after determining that the detection result of the target application is an unknown application type, the method further includes: Obtaining a new application type according to the type labeling result of the target application under the unknown application type; Determine the number of sequences of the actual interface call sequences corresponding to the new application type. When the number of sequences reaches a quantity threshold, train the corresponding autoencoder according to each actual interface call sequence corresponding to the new application type to obtain the autoencoder and normal distribution function corresponding to the new application type.

6. The method according to claim 3, characterized in that If the maximum probability is greater than a preset threshold of the detection application type corresponding to the maximum probability, then after taking the detection application type as the detection result of the target application, the method further includes: According to the actual interface call sequence corresponding to the target application, a sample interface call sequence newly added to the detection application type is obtained; generating a plurality of second random vectors that obey a normal distribution function corresponding to the detection application type, and decoding the plurality of second random vectors according to a decoder corresponding to an autoencoder of the detection application type to obtain a plurality of pseudo-coding sequences; A new training set is obtained according to the multiple pseudo-coding sequences and the newly added sample interface calling sequence, and the autoencoder and normal distribution function for detecting the application type are updated according to the new training set.

7. An application detection device for an intelligent measurement terminal, characterized in that: The device comprises: An autoencoder acquisition module is configured to acquire autoencoders corresponding to respective application types; the autoencoders are trained based on sample interface call sequences of platform interfaces by sample applications of the application types; the plurality of autoencoders each have a corresponding normal distribution function, the normal distribution function being determined based on sample call sequence features corresponding to respective sample interface call sequences of the same application type; a detection probability determination module, configured to, for each application type, input an actual interface call sequence of the target application to be detected in the intelligent measurement terminal to the platform interface into an autoencoder corresponding to the application type, obtain actual call sequence features output by the autoencoder, and determine a detection probability that the target application belongs to the application type based on the actual call sequence features and a normal distribution function corresponding to the autoencoder; The detection result acquisition module is used to determine the application type detection result of the target application according to each of the detection probabilities.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Method and device for detecting abnormal access of interface of power mobile terminal

    CN115080972A

  • Time sequence anomaly detection method and system based on variational automatic encoder and Shaplet

    CN117216757A

  • Open source software vulnerability detection method and device, equipment, medium and program product

    CN118036013A

  • Power system network security threat monitoring and early warning method and device, power equipment, computer storage medium and program product

    CN120128389A

  • Detecting device, detecting method, and detecting program

    US20210264285A1