Program identification method and device, server and computer readable storage medium
By communicating between the server and the terminal device, program running information is obtained and a target recognition model is used to determine whether it is a target program. This solves the problem of some automatically running programs being erroneously blocked and improves the user experience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHENZHEN TCL DIGITAL TECH CO LTD
- Filing Date
- 2025-12-04
- Publication Date
- 2026-04-10
AI Technical Summary
Existing technologies, when controlling device power consumption, sometimes result in the incorrect blocking of some automatically running business programs, leading to a poor user experience.
The system communicates with the terminal device to obtain program running information, identifies and determines target feature information, uses a target recognition model to determine whether it is a target program, and provides target recognition results to decide whether to intercept it.
It accurately identifies programs that do not need to be blocked, improving the user experience and avoiding unnecessary program blocking.
Smart Images

Figure CN121834802A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of electronic information, in particular to a program identification method and device, a server and a computer readable storage medium. BACKGROUND
[0002] In the prior art, intelligent electronic devices control the power consumption of the devices under the premise of ensuring certain performance, for example, controlling application startup at the system level, and intercepting behaviors that are not initiated by the user, such as application startup after accepting a broadcast background, and mutual keep-alive of a whole set of applications. By intercepting rogue application programs, the energy consumption of the system is reduced. However, some automatically running programs in the background are also mechanisms provided by the system. Accordingly, some objective business programs are implemented in this way, and if such business is intercepted by the system, it will result in poor user experience and complaints. Therefore, it is necessary to prevent some programs from being incorrectly intercepted. SUMMARY
[0003] The present application provides a program identification method that can identify programs that do not need to be intercepted.
[0004] In a first aspect, the present application provides a program identification method applied to a server, the server being in communication connection with a terminal device, and the method comprising: obtaining program running information corresponding to an initial program that has not been intercepted sent by the terminal device; determining target feature information of the initial program that has not been intercepted according to the program running information; identifying whether the initial program that has not been intercepted is a target program according to the target feature information, to obtain a target identification result.
[0005] In some embodiments of the present application, the target feature information of the initial program that has not been intercepted includes target field feature information and target association feature information. The method further comprises: extracting features of a field corresponding to the initial program that has not been intercepted according to the program running information, to determine the target field feature information of the target feature information of the initial program that has not been intercepted; extracting features of association information corresponding to the initial program that has not been intercepted according to the program running information, to determine the target association feature information of the target feature information of the initial program that has not been intercepted.
[0006] In some embodiments of the present application, the target correlation feature information includes: a number of times that the initial non-intercepted program returns to the foreground within a target time period, a number of clicks of the initial non-intercepted program within the target time period, memory occupation information of the initial non-intercepted program within the target time period, processor occupation information of the initial non-intercepted program within the target time period, foreground residence time of the initial non-intercepted program, cleaning information of the initial non-intercepted program within the target time period, a program score corresponding to the initial non-intercepted program, and demand information of whether the initial non-intercepted program is demanded by a user.
[0007] In some embodiments of the present application, the identifying whether the initial non-intercepted program is a target program according to the target feature information includes: According to a target identification model, the target feature information is identified to determine whether the initial non-intercepted program is a target program, and the target identification model is obtained according to a target training method. The target training method includes: A target training set is obtained, the target training set includes each training sample, each training sample corresponds to a true label, and each training sample is divided into a target sample set and a target test set. The target identification model is trained according to the target sample set and the target test set.
[0008] In some embodiments of the present application, after the target identification result is obtained by identifying whether the initial non-intercepted program is a target program according to the target feature information, the method further includes: The target identification result is sent to the terminal device, so that the terminal device determines whether the initial non-intercepted program needs to be intercepted according to the target identification result.
[0009] In some embodiments of the present application, the terminal device is in communication connection with a server, and the method includes: A current starting program is obtained. According to a target blacklist, it is determined whether the current starting program is an initial non-intercepted program. If the current starting program is the initial non-intercepted program, program running information corresponding to the initial non-intercepted program is sent to the server.
[0010] In some embodiments of the present application, after the initial non-intercepted program corresponding program running information is sent to the server, the method further includes: A target identification result sent by the server is obtained. if the target identification result indicates that the initial non-intercepted program is identified as a target intercepted program; adding the initial non-intercepted program to the target blacklist to intercept the initial non-intercepted program.
[0011] In a second aspect, the present application also provides a program identification device, applied to a server, the server being in communication connection with a terminal device, and the device comprising: a obtaining module, configured to obtain program running information corresponding to an initial non-intercepted program sent by the terminal device; a determining module, configured to determine target feature information of the initial non-intercepted program according to the program running information; a processing module, configured to identify whether the initial non-intercepted program is a target program according to the target feature information, and obtain a target identification result.
[0012] In a third aspect, the present application also provides a server, comprising a processor, a memory, and a computer program stored in the memory and executable on the processor, and the processor executes the computer program to implement the steps in any of the program identification methods.
[0013] In a fourth aspect, the present application also provides a computer readable storage medium, having a computer program stored thereon, and the computer program is executed by a processor to implement the steps in any of the program identification methods.
[0014] The program identification method provided by the present application can first obtain program running information corresponding to an initial non-intercepted program sent by a terminal device. Then, according to the obtained corresponding program running information, target feature information of the initial non-intercepted program can be determined, and whether the initial non-intercepted program needs to be intercepted can be identified according to the target feature information. Therefore, the terminal device can effectively identify programs that need to be intercepted and programs that do not need to be intercepted. BRIEF DESCRIPTION OF DRAWINGS
[0015] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0016] Figure 1 is a scene schematic diagram of a program identification system provided in the embodiments of the present application; Figure 2 is a flowchart schematic diagram of one embodiment of a program identification method in the embodiments of the present application; Figure 3 This is a schematic diagram of a functional module of the program identification device in an embodiment of this application; Figure 4 This is a schematic diagram of the server structure in an embodiment of this application. Detailed Implementation
[0017] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0018] In the description of this application, it should be understood that the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this application, "multiple" means two or more, unless otherwise explicitly specified.
[0019] In this application, the term "exemplary" is used to mean "used as an example, illustration, or description." Any embodiment described as "exemplary" in this application is not necessarily to be construed as being more preferred or advantageous than other embodiments. Furthermore, it is understood that in the specific embodiments of this application, user information, user data, and other related data are involved. When the above embodiments of this application are applied to specific products or technologies, user permission or consent is required, and the collection, use, and processing of related data must comply with the relevant laws, regulations, and standards of the relevant countries and regions.
[0020] To enable any person skilled in the art to implement and use this application, the following description is provided. In this description, details are set forth for purposes of explanation. It should be understood that those skilled in the art will recognize that this application can be implemented without using these specific details. In other instances, well-known structures and processes will not be described in detail to avoid obscuring the description of this application with unnecessary detail. Therefore, this application is not intended to be limited to the embodiments shown, but is consistent with the broadest scope of the principles and features disclosed in this application.
[0021] Please see Figure 1 , Figure 1This is a schematic diagram illustrating a scenario of the program identification method provided in an embodiment of this application. The program identification system may include a server 100 and a terminal device 200. The server 100 and the terminal device 200 are communicatively connected. The server 100 can transmit data to the terminal device 200, and the terminal device 200 can also transmit data to the server 100, such as... Figure 1 The server 100 can process the program identification method mentioned in this application based on the program running information corresponding to the initial unintercepted program sent by the terminal device 200.
[0022] In this embodiment, server 100 includes, but is not limited to, a standalone server, or a server network or server cluster, including, but not limited to, computers, network hosts, single network servers, multiple network server sets, or cloud servers composed of multiple servers. The cloud server can be composed of a large number of computers or network servers based on cloud computing.
[0023] In this embodiment of the application, the terminal device 200 may include, but is not limited to, desktop computers, portable computers, network servers, handheld computers (Personal Digital Assistants, PDAs), tablet computers, wireless terminal devices, embedded devices, mobile phones, televisions, virtual reality devices, etc.
[0024] In the embodiments of this application, the server 100 and the terminal device 200 can communicate through any communication method, including but not limited to mobile communication based on the 3rd Generation Partnership Project (3GPP), Long Term Evolution (LTE), and Worldwide Interoperability for Microwave Access (WiMAX), or computer network communication based on the TCP / IP Protocol Suite (TCP / IP) and User Datagram Protocol (UDP).
[0025] Those skilled in the art will understand that Figure 1 The application environment shown is merely one application scenario of the solution in this application and does not constitute a limitation on the application scenario of the solution in this application. Other application environments may include those that are more specific to this application. Figure 1 The number of servers and backend devices shown is more or less, for example Figure 1Only one server or backend device is shown in the document. The program identifies that the system may also include one or more other servers and servers that can process data, which are not specifically limited here.
[0026] It should be noted that, Figure 1 The schematic diagram of the program recognition system shown is merely an example. The program recognition system and scenarios described in this application are intended to more clearly illustrate the technical solutions of this application and do not constitute a limitation on the technical solutions provided in this application. As those skilled in the art will know, with the evolution of program recognition systems and the emergence of new business scenarios, the technical solutions provided in this application are also applicable to similar technical problems.
[0027] like Figure 2 As shown, Figure 2 This is a flowchart illustrating one embodiment of the program identification method in this application. The method is applied to a server and may include the following steps 201-203: 201. Obtain the program running information corresponding to the initial unintercepted program sent by the terminal device.
[0028] In this embodiment of the application, the server can communicate with the user's terminal device, and it can communicate through any communication protocol. This embodiment of the application does not limit it.
[0029] Terminal devices typically possess a certain degree of program interception capability, thus filtering some program code through their own interception system. However, in some cases, certain programs have strong anti-interception capabilities or are highly stealthy. Therefore, some programs may evade the terminal device's own interception system. Based on this, in this embodiment, the initially unblocked programs are those that have not been intercepted after the terminal device's initial interception process. These programs may include malicious programs or programs requested by the user.
[0030] Furthermore, in this embodiment, the program running information corresponding to the initially unintercepted program can be understood as the attribute information corresponding to the initially unintercepted program, such as identity information and related program code.
[0031] 202. Based on the program execution information, determine the target characteristic information of the initially unintercepted program.
[0032] Based on the above steps, in this embodiment of the application, the initially unblocked program includes corresponding program code, and programs with crawler-like characteristics or those that execute automatically in the background all have corresponding scraping code. Therefore, if program code with scraping actions can be identified, it can be determined that the initially unblocked program infringes on user rights or is detrimental to the user, and needs to be blocked. Therefore, in this embodiment of the application, it can be determined whether the program code of the initially unblocked program has the corresponding characteristics of a scraping program.
[0033] It should be noted that, in this embodiment, the target feature information may not only represent the characteristics of the scraping program, but may also include code features that maliciously seize computer resources, such as bypassing user authorization and stealing computer computing resources to provide cloud computing services. These programs should also be considered as intercepted programs. Therefore, the target feature information can be of various types, and this embodiment does not limit it.
[0034] Furthermore, in this application embodiment, feature extraction can be performed not only through AI neural networks, but also through any model architecture and training method; this application embodiment does not limit these methods. Alternatively, a code repository can be established, storing various types of malicious program code. By comparing the program code corresponding to the initially unblocked program with the malicious code in the code repository, it can be determined whether it is a program that needs to be intercepted. Therefore, program fragments in the initially unblocked program that match malicious code can also be considered as specific feature information. In this regard, this application embodiment does not limit the target feature information.
[0035] 203. Based on the target feature information, identify whether the initially unintercepted program is the target program and obtain the target identification result.
[0036] Based on the above steps, the program code of the initially uninterrupted program itself can be used as feature information, or an AI neural network can be used to extract feature information from the program code of the initially uninterrupted program. Identification results can be obtained through either code comparison or feature comparison. If it does not conform to malicious code, crawler code, etc., then a mismatched target identification result is obtained; if it conforms to malicious code, crawler code, etc., then a matched target identification result is obtained.
[0037] To better implement the embodiments of this application, in one embodiment, the target feature information of the initially unintercepted program includes target field feature information and target association feature information; determining the target feature information of the initially unintercepted program based on program running information includes: Based on the program execution information, feature extraction is performed on the fields corresponding to the initially unintercepted program to determine the target field feature information of the initial unintercepted program; based on the program execution information, feature extraction is performed on the associated information corresponding to the initially unintercepted program to determine the target associated feature information of the initial unintercepted program.
[0038] The above embodiments provide a scheme for feature extraction and identification based on the program itself when it is initially not intercepted. However, in order to make the identification results more accurate, this application embodiment also provides a feature extraction scheme to improve the identification accuracy.
[0039] Specifically, in this embodiment, the target field feature information may include the application name, program code, etc., of the program itself, which is the same as the extraction method described in the above embodiments. Based on this, the target associated feature information in this embodiment may be features associated with the initially uninterrupted program, rather than features of the program itself. For example, log data generated during program execution; feature extraction from this log data can also reflect the program's purpose. For example, by analyzing the logs of the initially uninterrupted program, the size of its data communication traffic can be obtained, and the communication traffic data can be used to analyze whether the initially uninterrupted program has a large amount of abnormal data communication. Alternatively, the number of times the initially uninterrupted program is actively launched by the user and its runtime can be analyzed. If the user actively launches the initially uninterrupted program many times and the runtime is also high, it can be proven that it is the program the user needs, regardless of whether it has crawler or malicious characteristics. Therefore, by extracting features from the target field feature information and the target associated feature information, the accuracy of subsequent identification results can be improved.
[0040] Furthermore, in this embodiment, the feature extraction methods for target field feature information and target associated feature information can be the same as those in the above embodiments, and will not be repeated here.
[0041] The above embodiments provide target association feature information that may include log data, startup data, etc., of the initially uninterrupted program. To better implement the embodiments of this application, in one embodiment, the target association feature information may further include: the number of times the initially uninterrupted program returned to the foreground within a target time period, the number of clicks on the initially uninterrupted program within the target time period, the memory usage information of the initially uninterrupted program within the target time period, the processor usage information of the initially uninterrupted program within the target time period, the foreground dwell time of the initially uninterrupted program, the cleanup information of the initially uninterrupted program within the target time period, the program rating corresponding to the initially uninterrupted program, and user demand information regarding whether the initially uninterrupted program is needed.
[0042] Specifically, the number of times the initially unblocked program returned to the foreground within the target time period, the number of clicks on the initially unblocked program within the target time period, and the foreground dwell time of the initially unblocked program can characterize the frequency of the initially unblocked program being in the foreground. If it is frequently in the foreground, it indicates that the user actively uses the program frequently, which means that the user is aware of the program, and the program is not a program that needs to be blocked. At the same time, the memory usage information and processor usage information of the initially unblocked program within the target time period can characterize whether the initially unblocked program is maliciously consuming computer resources. The cleanup information of the initially unblocked program within the target time period can characterize whether the program has been detected and killed by automatic memory cleanup. If it is detected and killed too much by memory cleanup, it can indicate that it is a program that is not important to the user. In addition, the program rating corresponding to the initially unblocked program can be obtained from the Internet. For example: AppName: Application name (vectorized); ReturnToForegroundCount: Number of times the application returned to the foreground within 1 minute; ClickCount: Number of clicks within the application within 1 minute; MemoryUsageMean: Average memory usage within 1 minute; CPUUsageMean: Average CPU usage within 1 minute; ForegroundDwellTime: Duration of the application when returning to the foreground; IsCleared: Whether the application was actively cleared within 1 minute (0 indicates no, 1 indicates yes); AppRating: Rating of the crawler application; UserNeeds: Whether the application meets user needs (tags), etc.
[0043] To better implement the embodiments of this application, in one embodiment, identifying whether an initially unintercepted program is a target program based on target feature information includes: Based on the target recognition model, the target feature information is identified to determine whether the initially unintercepted program is the target program. The target recognition model is obtained according to the target training method. The target training method includes: obtaining the target training set, which includes each training sample, each training sample has a corresponding real label, and each training sample is divided into the target sample set and the target test set; and training the target recognition model based on the target sample set and the target test set.
[0044] The above embodiments provide a method for feature extraction using AI neural networks, and training can be performed using any training method. This application also provides a specific training method, for example: multiple sample sets can be set, each containing both a training set and a test set. Assuming each sample set can include 100 code samples, 80 of these samples can be used as the training set and input into the model for training. The remaining 20 samples can be used as the test set and input into the model to verify the recognition accuracy of the first 80 training samples. If the accuracy does not reach a set value, the model parameters can be adjusted to continue training.
[0045] To better implement the embodiments of this application, in one embodiment, after identifying whether the initially unintercepted program is a target program based on target feature information and obtaining the target identification result, the method further includes: The target identification result is sent to the terminal device so that the terminal device can determine whether the initially unblocked program needs to be blocked based on the target identification result.
[0046] The above embodiments provide a scheme and related process for identifying programs that need to be blocked. Based on this, if the server can provide the program identification result, it can return the result to the user's terminal device to help the terminal device block the program. For example, the terminal device can determine whether a program running on the terminal device needs to be blocked based on the target identification result returned by the server. If it is determined that a program needs to be blocked, the terminal device can perform the blocking action. Whether this is done by shutting down the program or by blocking it through an antivirus program is not limited in this embodiment.
[0047] To better implement the embodiments of this application, in one embodiment, a solution is also provided, which is applied to a terminal device, the terminal device communicating with a server, the method including: Obtain the currently launched program; determine whether the currently launched program is an initially unblocked program based on the target blacklist; if the currently launched program is an initially unblocked program, send the program running information corresponding to the initially unblocked program to the server.
[0048] This application provides a scheme for server-side program identification. The input data used by the server for identification is the relevant data corresponding to the initially uninterrupted program sent by the terminal device. Therefore, the terminal device needs to perform a preliminary program interception process before sending data. This application provides an implementation scheme for initial interception.
[0049] Specifically, the terminal device can set up a blacklist, for example, based on historical interception records or user-specified interception targets, adding programs corresponding to the interception records and programs corresponding to user-specified targets to the blacklist. When a program starts on the terminal device, it is compared with programs in the blacklist. If it exists in the blacklist, it can be directly intercepted without needing to identify malicious code, thus improving interception efficiency. If it does not exist in the blacklist, the data corresponding to the initially uninterrupted program is then sent to the server.
[0050] To better implement the embodiments of this application, in one embodiment of this application, after sending the program execution information corresponding to the initially unintercepted program to the server, the method further includes: Obtain the target identification result sent by the server; if the target identification result indicates that the initially unintercepted program has been identified as a target interceptor program; add the initially unintercepted program to the target blacklist to intercept the initially unintercepted program.
[0051] The above embodiments provide a scheme for initial interception using a blacklist by a terminal device. Since the server sends the target identification results for program interception to the terminal device, if the terminal device receives a program that needs to be intercepted, it can also add the initially uninterrupted program to the blacklist. In subsequent processes, if the initially uninterrupted program is restarted, it will be intercepted by the initial interception process and will not be transmitted to the server again, thereby improving the interception efficiency.
[0052] To better implement the program identification method in the embodiments of this application, this application also provides a program identification device, applied to a server, wherein the server and a terminal device are communicatively connected, such as... Figure 3 As shown, the device 300 includes: The acquisition module 301 is used to acquire program running information corresponding to the initial unintercepted program sent by the terminal device; The determination module 302 is used to determine the target feature information of the initially unintercepted program based on the program running information; The processing module 303 is used to identify whether the initially unintercepted program is the target program based on the target feature information, and obtain the target identification result.
[0053] The program identification device provided in this application has an acquisition module 301 that first acquires the program execution information corresponding to the initially unintercepted program sent by the terminal device. Then, based on the acquired program execution information, a determining module 302 can determine the relevant target feature information of the initially unintercepted program. Subsequently, a processing module 303 can identify whether the program needs to be intercepted based on this target feature information. Therefore, it can help the terminal device effectively identify programs that need to be intercepted and programs that do not need to be intercepted.
[0054] In some embodiments of this application, the target feature information of the initially unintercepted program includes target field feature information and target association feature information, and the determining module 302 is specifically used for: Based on the program execution information, feature extraction is performed on the fields corresponding to the initially unintercepted program to determine the target field feature information of the initially unintercepted program. Based on the program execution information, feature extraction is performed on the associated information corresponding to the initially unintercepted program to determine the target associated feature information of the initially unintercepted program.
[0055] In some embodiments of this application, the target association feature information involved in the determination module 302 includes: the number of times the initially unblocked program returns to the foreground within the target time period, the number of clicks on the initially unblocked program within the target time period, the memory usage information of the initially unblocked program within the target time period, the processor usage information of the initially unblocked program within the target time period, the foreground dwell time of the initially unblocked program, the cleanup information of the initially unblocked program within the target time period, the program rating corresponding to the initially unblocked program, and the user's demand information regarding whether the initially unblocked program is needed.
[0056] In some embodiments of this application, the processing module 303 is specifically used for: Based on the target recognition model, the target feature information is identified to determine whether the initially uninterrupted program is the target program. The target recognition model is obtained based on the target training method. Target training methods include: Obtain the target training set, which includes each training sample. Each training sample has a corresponding real label. Each training sample is divided into the target sample set and the target test set. The target recognition model is trained based on the target sample set and the target test set.
[0057] In some embodiments of this application, the processing module 303 is further configured to: The target identification result is sent to the terminal device so that the terminal device can determine whether the initially unblocked program needs to be blocked based on the target identification result.
[0058] To better implement the program identification method in the embodiments of this application, in addition to the program identification method, this application also provides a program identification device, applied to a terminal device, wherein the terminal device is communicatively connected to a server, and the method includes: Terminal acquisition module, used to acquire the currently running program; The terminal determination module is used to determine whether the currently launched program is an initially unblocked program based on the target blacklist; The terminal interception module is used to send the program running information of the initially unintercepted program to the server if the currently launched program is one that was not initially intercepted.
[0059] In some embodiments of this application, the terminal determination module is specifically used for: Obtain the target recognition results sent by the server; If the target identification result indicates that the initially unintercepted program has been identified as a target intercepting program; Add the initially unblocked program to the target blacklist to block the initially unblocked program.
[0060] This application also provides a server that integrates any of the program identification methods provided in this application, such as... Figure 4 As shown, it illustrates a schematic diagram of the server structure involved in an embodiment of this application. Specifically: The server may include components such as a processor 401 with one or more processing cores, a memory 402 with one or more computer-readable storage media, a power supply 403, and an input unit 404. Those skilled in the art will understand that... Figure 4 The server architecture shown does not constitute a limitation on the server and may include more or fewer components than illustrated, or combine certain components, or have different component arrangements. Wherein: Processor 401 is the control center of the server, connecting various parts of the server through various interfaces and lines. It performs various server functions and processes data by running or executing software programs and / or modules stored in memory 402, and by calling data stored in memory 402, thereby providing overall monitoring of the server. Optionally, processor 401 may include one or more processing cores; processor 401 may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor. Preferably, processor 401 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, user interface, and applications, and the modem processor mainly handles wireless communication. It is understood that the aforementioned modem processor may not be integrated into processor 401.
[0061] The memory 402 can be used to store software programs and modules. The processor 401 executes various functional applications and data processing by running the software programs and modules stored in the memory 402. The memory 402 may mainly include a program storage area and a data storage area. The program storage area may store the operating system and at least one application program required for a function; the data storage area may store data created according to the use of the server, etc. In addition, the memory 402 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device. Accordingly, the memory 402 may also include a memory controller to provide the processor 401 with access to the memory 402.
[0062] The server also includes a power supply 403 that supplies power to the various components. Preferably, the power supply 403 can be logically connected to the processor 401 through a power management system, thereby enabling functions such as charging, discharging, and power consumption management through the power management system. The power supply 403 may also include one or more DC or AC power supplies, recharging systems, power fault detection circuits, power converters or inverters, power status indicators, and other arbitrary components.
[0063] The server may also include an input unit 404, which can be used to receive input numeric or character information, and generate keyboard, mouse, joystick, optical or trackball signal inputs related to user settings and function control.
[0064] Although not shown, the server may also include a display unit, etc., which will not be described in detail here. Specifically, in this embodiment, the processor 401 in the server loads the executable files corresponding to the processes of one or more applications into the memory 402 according to the following instructions, and the processor 401 runs the applications stored in the memory 402 to realize various functions, such as: Obtain the program execution information corresponding to the initial unintercepted program sent by the terminal device; Based on the program execution information, determine the target characteristic information of the initially unintercepted program; Based on the target feature information, it is determined whether the initially unintercepted program is the target program, and the target identification result is obtained.
[0065] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be performed by instructions, or by instructions controlling related hardware. These instructions can be stored in a computer-readable storage medium and loaded and executed by a processor.
[0066] Therefore, embodiments of this application provide a computer-readable storage medium, which may include: read-only memory (ROM), random access memory (RAM), a magnetic disk, or an optical disk, etc. A computer program is stored thereon, and the computer program is loaded by a processor to execute the steps in any of the program identification methods provided in embodiments of this application. For example, the computer program loaded by the processor can execute the following steps: Obtain the program execution information corresponding to the initial unintercepted program sent by the terminal device; Based on the program execution information, determine the target characteristic information of the initially unintercepted program; Based on the target feature information, it is determined whether the initially unintercepted program is the target program, and the target identification result is obtained.
[0067] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the detailed descriptions of other embodiments above, which will not be repeated here.
[0068] In practice, each of the above units or structures can be implemented as an independent entity or can be arbitrarily combined to be implemented as the same or several entities. For the specific implementation of each of the above units or structures, please refer to the previous method embodiments, which will not be repeated here.
[0069] For details on the implementation of each of the above operations, please refer to the previous examples, which will not be repeated here.
[0070] The above provides a detailed description of a program identification method and apparatus provided in the embodiments of this application. Specific examples have been used to illustrate the principles and implementation methods of this application. The description of the above embodiments is only for the purpose of helping to understand the method and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.
Claims
1. A program identification method, characterized in that, Applied to a server, wherein the server is communicatively connected to a terminal device, the method includes: Obtain the program execution information corresponding to the initial unintercepted program sent by the terminal device; Based on the program execution information, determine the target feature information of the initial unintercepted program; Based on the target feature information, it is determined whether the initially unintercepted program is the target program, and the target identification result is obtained.
2. The program identification method according to claim 1, characterized in that, The target feature information of the initial unintercepted program includes target field feature information and target association feature information; The step of determining the target feature information of the initially unintercepted program based on the program execution information includes: Based on the program running information, feature extraction is performed on the fields corresponding to the initial unintercepted program to determine the target field feature information of the target feature information of the initial unintercepted program; Based on the program running information, feature extraction is performed on the associated information corresponding to the initial unintercepted program to determine the target associated feature information of the initial unintercepted program.
3. The program identification method according to claim 2, characterized in that, The target associated feature information includes: the number of times the initially unblocked program returned to the foreground within the target time period, the number of clicks on the initially unblocked program within the target time period, the memory usage information of the initially unblocked program within the target time period, the processor usage information of the initially unblocked program within the target time period, the foreground dwell time of the initially unblocked program, the cleanup information of the initially unblocked program within the target time period, the program rating corresponding to the initially unblocked program, and the user's demand information regarding whether the initially unblocked program is needed.
4. The program identification method according to claim 1, characterized in that, The step of identifying whether the initially unintercepted program is a target program based on the target feature information includes: The target feature information is identified based on the target recognition model to determine whether the initial unintercepted program is a target program. The target recognition model is obtained based on the target training method. The target training method includes: Obtain the target training set, which includes various training samples, each training sample having a corresponding real label, and each training sample is divided into the target sample set and the target test set; The target recognition model is trained based on the target sample set and the target test set.
5. The program identification method according to claim 1, characterized in that, After identifying whether the initially unintercepted program is a target program based on the target feature information and obtaining the target identification result, the method further includes: The target identification result is sent to the terminal device so that the terminal device can determine whether the initially uninterrupted program needs to be intercepted based on the target identification result.
6. A program identification method, characterized in that, Applied to a terminal device that communicates with a server, the method includes: Get the currently running program; Based on the target blacklist, determine whether the currently launched program is an initially unblocked program; If the currently launched program is the initial unintercepted program, the program running information corresponding to the initial unintercepted program is sent to the server.
7. The program identification method according to claim 6, characterized in that, After sending the program execution information corresponding to the initially unintercepted program to the server, the method further includes: Obtain the target identification result sent by the server; If the target identification result indicates that the initially unintercepted program is identified as a target intercepting program; The initially unblocked program is added to the target blacklist to intercept the initially unblocked program.
8. A program identification device, characterized in that, Applied to a server, wherein the server is communicatively connected to a terminal device, the device includes: The acquisition module is used to acquire program running information corresponding to the initial unintercepted program sent by the terminal device; The determination module is used to determine the target feature information of the initially unintercepted program based on the program execution information; The processing module is used to identify whether the initially unintercepted program is a target program based on the target feature information, and to obtain the target identification result.
9. A server, characterized in that, The server includes a processor, a memory, and a computer program stored in the memory and executable on the processor, the processor executing the computer program to implement the steps of the program identification method according to any one of claims 1 to 5.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, which is executed by a processor to implement the steps of the program identification method according to any one of claims 1 to 5.