Tracing analysis method and device, storage medium and electronic equipment

By combining a multi-dimensional underlying database and tracing rules, efficient and accurate tracing of network data is achieved, solving the problem of difficulty in identifying criminals on the Internet and generating detailed tracing reports.

CN121940198APending Publication Date: 2026-04-28BEIJING HONGTENG INTELLIGENT TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING HONGTENG INTELLIGENT TECH CO LTD
Filing Date
2026-01-29
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

Existing technologies struggle to effectively pinpoint the true identities of criminals online, especially when internet identities are virtual and deceptive, making case investigations extremely difficult.

Method used

By collecting big data from the Internet, utilizing multi-dimensional underlying databases and traceability rules, multi-dimensional traceability processing is performed to determine the information of related devices and generate traceability result reports.

Benefits of technology

It improves the response efficiency and accuracy of network data tracing, and generates tracing result reports that are easy to view and use.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121940198A_ABST
    Figure CN121940198A_ABST
Patent Text Reader

Abstract

The invention provides a traceability analysis method and device, a storage medium and electronic equipment, and the method is applied to the technical field of computers, and comprises the steps: determining a target traceability type corresponding to network data to be traced, and carrying out the multi-dimensional traceability processing based on a traceability rule corresponding to the target traceability type and a multi-dimensional underlying database, and determining associated equipment information corresponding to the to-be-traced network data, performing traceability analysis processing based on the associated equipment information, and generating a traceability result report corresponding to the to-be-traced network data. According to the method, the associated equipment information can be determined through the traceability type in combination with the multi-dimensional underlying database, the response efficiency and accuracy of network data traceability are improved, and the result report is generated so that related personnel can check and use the traceability result conveniently.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and more specifically, to a traceability analysis method, apparatus, storage medium, and electronic device in the field of computer technology. Background Technology

[0002] With the rapid development of the internet, it has brought many conveniences to society and people's lives. More and more people use the internet frequently in their work and life, leaving traces online. This has also provided opportunities for criminals, and more and more dangers from the internet are affecting the personal and property safety of normal people. Current technologies often use methods such as surveillance video, money transfer transactions, and mobile communication to locate criminals. However, with the development of internet technology, the identities of criminals on the internet are virtual and deceptive, making it difficult to locate their identities. Therefore, there is a need to provide a method that can trace the source of network data. Summary of the Invention

[0003] This application provides a traceability analysis method, apparatus, storage medium, and electronic device. The method can determine the associated device information by combining the traceability type with a multi-dimensional underlying database, thereby improving the response efficiency and accuracy of network data traceability and generating a result report to facilitate relevant personnel to view and use the traceability results.

[0004] In a first aspect, embodiments of this application provide a source tracing analysis method, the method comprising: Determine the target tracing type corresponding to the network data to be traced; Based on the tracing rules corresponding to the target tracing type and the multi-dimensional underlying database, multi-dimensional tracing processing is performed to determine the associated device information corresponding to the network data to be traced. Based on the associated device information, a source tracing analysis is performed to generate a source tracing result report corresponding to the network data to be traced.

[0005] Secondly, embodiments of this application provide a traceability analysis device, the device comprising: The source tracing type determination unit is used to determine the target source tracing type corresponding to the network data to be traced. The multi-dimensional tracing unit is used to perform multi-dimensional tracing processing based on the tracing rules corresponding to the target tracing type and the multi-dimensional underlying database, and to determine the associated device information corresponding to the network data to be traced. The source tracing analysis unit is used to perform source tracing analysis based on the associated device information and generate a source tracing result report corresponding to the network data to be traced.

[0006] Thirdly, embodiments of this application provide a computer storage medium storing a plurality of instructions adapted for loading by a processor and executing the above-described method steps.

[0007] Fourthly, embodiments of this application provide an electronic device that may include: a processor and a memory; wherein the memory stores a computer program adapted to be loaded by the processor and to execute the above-described method steps.

[0008] In one or more embodiments of this application, a target tracing type corresponding to the network data to be traced is determined. Multidimensional tracing processing is performed based on the tracing rules corresponding to the target tracing type and a multidimensional underlying database to determine the associated device information corresponding to the network data to be traced. Tracing analysis is then performed based on the associated device information to generate a tracing result report corresponding to the network data to be traced. By using the tracing type and combining it with the multidimensional underlying database to determine the associated device information, the response efficiency and accuracy of network data tracing are improved, and the generated result report facilitates the viewing and use of the tracing results by relevant personnel. Attached Figure Description

[0009] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0010] Figure 1 This is a system architecture diagram for source tracing analysis provided in an embodiment of this application; Figure 2 This is a flowchart illustrating a source tracing analysis method provided in an embodiment of this application; Figure 3 This is a schematic diagram illustrating the process of constructing a multidimensional underlying database according to an embodiment of this application; Figure 4 This is a schematic diagram of a network address tracing process provided in an embodiment of this application; Figure 5 This is a schematic diagram of a domain name tracing process provided in an embodiment of this application; Figure 6 This is a schematic diagram of a program file tracing process provided in an embodiment of this application; Figure 7 This is a schematic diagram of a result report generation process provided in an embodiment of this application; Figure 8 This is a schematic diagram of the structure of a traceability analysis device provided in an embodiment of this application; Figure 9 This is a schematic diagram of the structure of a traceability analysis device provided in an embodiment of this application; Figure 10 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0011] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0012] The development and widespread adoption of the internet have brought immense convenience to people's work and lives, such as mobile payments, online shopping, remote work, and even cloud-based teaching. The internet has penetrated every aspect of people's work, life, and entertainment. Every time people browse the internet, they leave traces—that is, online data—making cybersecurity extremely important in today's society. In existing technologies, relevant departments mainly use methods such as video surveillance, money transfers, and mobile communications to locate criminals. However, with the development of the internet, identity representation is often highly virtualized. For example, criminals often use virtual phone numbers, social media accounts, and domain names to conduct online operations. Online identities are generally virtual and deceptive, making it difficult to locate the true identities of criminals and significantly increasing the difficulty of investigating cases. This application provides a source tracing analysis method that can trace the source of specified network data by collecting big data from the internet and correlating the relationships between internet data. The source tracing analysis method provided in this application can be implemented using a computer program and can run on a source tracing analysis device based on the von Neumann architecture. This computer program can be integrated into applications or run as a standalone tool application.

[0013] Please see also Figure 1This application provides a system architecture diagram for traceability analysis, which can be composed of multiple modules such as a data center, an operation management center, graph analysis, data traceability, traceability analysis, and intelligent reporting. The data center, operation management center, and graph analysis can be used to form a multi-dimensional underlying database, providing underlying data support for the traceability analysis device to perform data traceability processing and traceability analysis on the network data to be traced. The data center can perform data access, data merging, data fusion, and data classification on various types of network data and store them. The operation management center can establish traceability rules corresponding to each traceability type. The traceability rules can be set by relevant personnel in the operation management center. Graph analysis can be used to perform correlation analysis on various types of network data collected and stored in the data center and generate correlation analysis relationships. Thus, a multi-dimensional underlying database is constructed based on the correlation analysis relationships between various types of network data and the data, which facilitates retrieval and calling of the multi-dimensional underlying database during subsequent multi-dimensional traceability processing and traceability analysis.

[0014] The data tracing module is used to process network data to be traced. This data can be network data sent to the tracing analysis device by users, relevant staff, or departments, or network data captured by the device from the internet. The module can include various tracing types, such as network address tracing, domain name tracing, and program file tracing. These types can be set initially by the tracing analysis device or configured by staff at the operations management center. The tracing analysis module analyzes the information obtained after data tracing, including profiling and tracing extension. The intelligent reporting module generates tracing result reports based on the information obtained from the analysis, which are then displayed to users, relevant staff, or departments, improving the response efficiency, accuracy, and visualization of network data tracing.

[0015] The source tracing analysis method provided in this application will be described in detail below with reference to specific embodiments.

[0016] Please see Figure 2 The diagram below illustrates a source tracing analysis method provided in this application. Figure 2 As shown, the method described in this application embodiment may include the following steps S101-S103.

[0017] S101, Determine the target tracing type corresponding to the network data to be traced.

[0018] Specifically, when users, relevant staff, or relevant departments need to perform source tracing analysis on any network data, they can send the network data as the source data to be traced to the source tracing analysis device. After receiving the source data, the source tracing analysis device can determine the target source tracing type corresponding to the source data. The source tracing type can be the top-level source tracing entry point for dividing the source data, and can be used to determine the data range, calculation method, etc. used in subsequent multi-dimensional source tracing processing and source tracing analysis processing.

[0019] Optionally, a risk monitoring model can be used to monitor and process network data generated on the Internet, obtaining detection results for the network data. These results include whether the network data is abnormal or normal. Abnormal network data is then identified as network data to be traced, thus achieving network risk monitoring. Abnormal network data refers to network data that poses a network security risk, while normal network data refers to network data generated by normal internet use. The risk monitoring model has the ability to determine whether network data is abnormal or normal at the feature vector level. This risk monitoring model can then be applied to the risk monitoring and processing of network data, thereby proactively identifying network risks and improving network data security.

[0020] S102, based on the tracing rules corresponding to the target tracing type and the multi-dimensional underlying database, perform multi-dimensional tracing processing to determine the associated device information corresponding to the network data to be traced.

[0021] Specifically, after determining the target tracing type, the corresponding tracing rules can be further determined. These rules can be a set of execution steps corresponding to the tracing type, used to determine how to progressively trace the network data to be traced from the multidimensional underlying database. These rules can be set by relevant personnel in the operations management center. The tracing analysis device can perform multidimensional tracing processing at the multidimensional underlying database based on the tracing rules corresponding to the target tracing type. According to the correlation analysis relationships between various network data in the multidimensional underlying database, it progressively retrieves the network data to be traced, thereby obtaining the associated device information corresponding to the network data. This associated device information can be terminal device information related to the network data to be traced, such as terminal configuration information, terminal files, software information, and network access records. The terminal devices related to the network data to be traced can be the terminal device that generated the network data, or other terminal devices associated with the terminal device that generated the network data.

[0022] S103, perform source tracing analysis based on associated device information, and generate a source tracing result report corresponding to the network data to be traced.

[0023] Specifically, after confirming the associated device information related to the network data to be traced, further source tracing analysis can be carried out based on the associated device information. For example, gang discovery and pseudonym tracking can be performed, and the information obtained can be summarized to generate a source tracing result report corresponding to the network data to be traced. The source tracing result report can display the associated device information, gang information, virtual identity information and other related case information obtained from the source tracing analysis, and the source tracing route of multi-dimensional source tracing and source analysis.

[0024] In this embodiment, a target tracing type corresponding to the network data to be traced is determined. Multidimensional tracing processing is performed based on the tracing rules corresponding to the target tracing type and a multidimensional underlying database to determine the associated device information corresponding to the network data to be traced. Tracing analysis is then performed based on the associated device information to generate a tracing result report corresponding to the network data to be traced. By using the tracing type and combining it with the multidimensional underlying database to determine the associated device information, the response efficiency and accuracy of network data tracing are improved, and the generated result report facilitates the viewing and use of the tracing results by relevant personnel.

[0025] Please see Figure 3 This document provides a schematic diagram illustrating the process of constructing a multi-dimensional underlying database, as described in an embodiment of this application. Figure 3 As shown, in one or more embodiments of this application, the following steps S201-S203 may be included before step S101.

[0026] S201: Collect multidimensional Internet data from the data source and perform data preprocessing on the multidimensional Internet data.

[0027] Specifically, various types of network data can be collected from data sources to form multidimensional Internet data. Data sources can include neuron tracking data, third-party data, and local operational data. Among them, neuron tracking data can come from real-time behavioral data such as tracking points on various terminal devices and application software. Third-party data can be data obtained from other databases or companies. Local operational data can be local historical network data and business system logs, etc.

[0028] The collected multidimensional internet data can then undergo data preprocessing, which may include data merging, data fusion, data classification, and data storage. This results in various types of network data, such as Internet Infrastructure Data, Endpoint Intelligence Data, Cyber-Crime & Gray-Production Data, and Black-Term Lexicon. Internet Infrastructure Data can be macro-level indicators and resource lists of the "physical + logical" foundation of the internet at the global or national level. It measures network scale, topology, performance, and development level, and may include address resources, domain name resources, bandwidth, and routing. Endpoint Intelligence Data can be atomic events of "behavior + environment + threat" collected in real time from terminal devices such as computers, mobile phones, and servers. It is used to characterize the host-level attack surface and malicious behavior trajectory, and may include system environment, software assets, processes, and network behavior. Cyber-Crime & Gray-Production Data can describe the people, accounts, resources, transactions, methods, and funds in "illegal or borderline" industry chains. It serves as a target database for combating cybercrime, and may include accounts, identities, attack resources, and method tags. Blacklist data is a collection of high-risk keywords, regular expressions, and semantic vectors that have been continuously labeled and graded. It is used to quickly match illegal text, rhetoric, advertisements, and traffic-driving content, such as fraudulent rhetoric, traffic-driving rhetoric, and code words.

[0029] S202, perform correlation analysis on the preprocessed multidimensional Internet data to generate correlation analysis relationships between the multidimensional Internet data.

[0030] Specifically, it can perform correlation analysis on multidimensional Internet data after data preprocessing, and perform data correlation and graph correlation on various types of network data, thereby generating horizontal and vertical correlation analysis relationships between various types of data.

[0031] Optionally, a graph engine can be used to perform association analysis on the preprocessed multidimensional internet data. The graph engine combines a distributed in-memory graph database with a parallel graph computing framework, enabling operations such as multi-hop association, community detection, shortest path, and centrality. In the association analysis, various types of data in the multidimensional internet data can be associated using Internet Protocol Addresses (IP), domain names, and filenames to create a knowledge graph. Alternatively, they can be associated using terminal devices, routes, and IP nodes. Further processing, such as automatic node expansion, association description, and node information viewing, can then generate association analysis relationships between the multidimensional internet data.

[0032] S203 constructs a multidimensional underlying database based on multidimensional Internet data and correlation analysis relationships.

[0033] Specifically, based on multidimensional Internet data and the correlation analysis relationships between multidimensional Internet data, a multidimensional underlying database is constructed. The source tracing analysis device can call the multidimensional underlying database in subsequent multidimensional source tracing and source tracing analysis processes, and retrieve network data based on the correlation analysis relationships therein.

[0034] Optionally, the multidimensional underlying database can be used as a microservice to support subsequent multidimensional tracing and analysis. The multidimensional underlying database is composed of multidimensional Internet data and related analysis relationships, which forms a queryable and scalable knowledge graph from the multidimensional Internet data.

[0035] In this embodiment, multidimensional internet data is collected from a data source, preprocessed, and then subjected to correlation analysis to generate correlation relationships between the multidimensional internet data. Based on the multidimensional internet data and these correlation relationships, a multidimensional underlying database is constructed. By collecting big data from the internet and performing correlation analysis, a queryable multidimensional underlying database is built, improving the efficiency of subsequent multidimensional tracing and source analysis.

[0036] In one or more embodiments of this application, the target tracing type includes network address tracing, domain name tracing, and program file tracing.

[0037] Specifically, the traceability type is used to define the top-level traceability entry point for the network data to be traced. Therefore, the target traceability type can include network address traceability, domain name traceability, and program file traceability.

[0038] Network address tracing can use IP addresses as the tracing entry point. The corresponding tracing rules can be to use the IP address of the network data to be traced as the tracing entry point to perform layer-by-layer parsing, thereby locating the source of the network data. For example, the IP address can be used as the tracing entry point to further parse the physical location, Media Access Control Address (MAC) or Authenticated Broadband Account (PPPoE / BRAS Account) of the network data to be traced.

[0039] Domain name tracing can be done by using the domain name as the tracing entry point. The corresponding tracing rules can be used to perform layer-by-layer resolution on the domain name of the network data to be traced, thereby locating the source of the network data. For example, the domain name can be used as the tracing source to further resolve the domain name registrant, registration email, domain name resolution drift chain, or domain name cluster with the same certificate, etc.

[0040] Program file tracing can start with the application package (APK) as the tracing entry point. The tracing rules corresponding to program file tracing can use the APK of the network data to be traced as the tracing entry point to perform layer-by-layer parsing, thereby locating the source of the network data to be traced. For example, the APK can be used as the tracing entry point to further parse and find related APKs with the same certificate, the same code segment, the same compilation environment, or repackaged family.

[0041] Understandably, the traceability rules corresponding to each traceability type can be set by relevant staff at the operation management center, taking into account the range of network data that the traceability analysis device can collect and the query permissions it possesses.

[0042] Please see Figure 4 This document provides a schematic diagram of a network address tracing process in an embodiment of this application. Figure 4 As shown, in one or more embodiments of this application, step S102 may include the following steps S301-S303.

[0043] S301, if the target tracing type is network address tracing, then determine the target network address corresponding to the network data to be traced.

[0044] Specifically, if the target tracing type is network address tracing, then the target network address corresponding to the network data to be traced can be determined. The target network address can include one or more network addresses, and the network address can be an IP address.

[0045] S302, based on the tracing rules corresponding to network address tracing, determines the associated terminal information, terminal access information, external connection behavior information and associated URL information of the target network address in the multi-dimensional underlying database.

[0046] Specifically, based on the tracing rules corresponding to network addresses and the correlation analysis between multidimensional Internet data, the associated terminal information, terminal access information, external connection behavior information, and associated URL information corresponding to the target network address are determined in the multidimensional underlying database.

[0047] Optionally, associated terminals that have interacted with the target network address within the first time window can be obtained from the multidimensional underlying database, and the device information of these associated terminals can be identified as associated terminal information. The first time window can be a period of time before the time point when the network data to be traced occurred, it can be the initial setting of the traceability analysis device, or it can be set by relevant personnel.

[0048] After identifying the associated terminal, the access requests initiated by the associated terminal can be obtained from the multidimensional underlying database, and terminal access information can be generated based on the access requests. The terminal access information may include the access object of the access request, the access time, and the protocol used.

[0049] It can also obtain network behaviors initiated by associated terminals to external networks from the multi-dimensional underlying database and generate external behavior information, which may include external network IP, uploaded data, and downloaded data.

[0050] After determining the target network address, associated network addresses that were accessed by the same terminal as the target network address within the second time window can be obtained from the multidimensional underlying database. Based on these associated network addresses, associated URL information can be generated. The associated URL information can include the complete Uniform Resource Locator (URL), domain name, subdomain, etc. of the associated network address. The second time window can be a period of time before the time point when the network data to be traced occurred. It can be the initial setting of the traceability analysis device or it can be set by relevant personnel. The first time window can be the same as or different from the second time window.

[0051] S303 generates associated device information corresponding to the network data to be traced based on associated terminal information, terminal access information, external connection behavior information, and associated URL information.

[0052] Specifically, based on the obtained associated terminal information, terminal access information, external connection behavior information, and associated URL information, the terminal devices related to the network data to be traced are identified and associated device information is generated.

[0053] In this embodiment, if the target tracing type is network address tracing, the target network address corresponding to the network data to be traced is determined. Based on the tracing rules corresponding to the network address tracing, the associated terminal information, terminal access information, external connection behavior information, and associated URL information of the target network address are determined in the multi-dimensional underlying database. Based on the associated terminal information, terminal access information, external connection behavior information, and associated URL information, the associated device information corresponding to the network data to be traced is generated. By performing tracing queries on the network address of the network data to be traced in the multi-dimensional underlying database, targeted tracing analysis for network address tracing types is achieved, improving the accuracy of tracing.

[0054] Please see Figure 5 This document provides a schematic diagram of a domain name tracing process in an embodiment of this application. For example... Figure 5 As shown, in one or more embodiments of this application, step S102 may include the following steps S401-S403.

[0055] S401, if the target tracing type is domain name tracing, then determine the target domain name corresponding to the network data to be traced.

[0056] Specifically, if the target tracing type is domain name tracing, then the target domain name corresponding to the network data to be traced can be determined, and the target domain name can include one or more domain names.

[0057] S402, based on the tracing rules corresponding to the domain name, determines the access terminal information, terminal download information, associated domain name information and associated URL information corresponding to the target domain name in the multi-dimensional underlying database.

[0058] Specifically, based on the tracing rules corresponding to the domain name and the correlation analysis between multidimensional Internet data, the access terminal information, terminal download information, associated domain name information, and associated URL information corresponding to the target domain name are determined in the multidimensional underlying database.

[0059] Optionally, access terminals that have interacted with the target domain name within the third time window can be obtained from the multidimensional underlying database, and the device information of these access terminals can be identified as access terminal information. The third time window can be a period of time before the time point when the network data to be traced occurred, it can be the initial setting of the traceability analysis device, or it can be set by relevant personnel.

[0060] After identifying the access terminal, the download data of the access terminal within the target domain can be further obtained from the multidimensional underlying database, and terminal download information can be generated based on this download data. The terminal download information may include the download data file name, download data size, download start time and download end time, etc.

[0061] After determining the target domain name, associated domain names with preset association analysis relationships with the target domain name can be identified in the multidimensional underlying database. Based on these associated domain names, associated domain name information can be generated. The preset association analysis relationships can include association analysis relationships such as having the same registrant, having the same registration email, or having the same certificate. The associated domain name information can include the certificate fingerprint, creation time, etc. of the associated domain name.

[0062] After identifying the associated domains, the associated network addresses referenced by the target domain and associated domains can be determined in the multidimensional underlying database. Based on these associated network addresses, associated URL information can be generated, which may include the complete URL of the associated network address.

[0063] S403 generates associated device information corresponding to the network data to be traced based on access terminal information, terminal download information, associated domain name information, and associated URL information.

[0064] Specifically, based on the obtained access terminal information, terminal download information, associated domain name information, and associated URL information, the terminal devices related to the network data to be traced are identified and associated device information is generated.

[0065] In this embodiment, if the target tracing type is domain name tracing, the target domain name corresponding to the network data to be traced is determined. Based on the tracing rules corresponding to the domain name tracing, the access terminal information, terminal download information, associated domain name information, and associated URL information corresponding to the target domain name are determined in the multi-dimensional underlying database. Based on the access terminal information, terminal download information, associated domain name information, and associated URL information, associated device information corresponding to the network data to be traced is generated. By performing tracing queries on the multi-dimensional underlying database using the domain name corresponding to the network data to be traced, targeted tracing analysis for the domain name tracing type is achieved, improving the accuracy of tracing.

[0066] Please see Figure 6 This provides a flowchart illustrating the process of tracing program files in an embodiment of this application. For example... Figure 6 As shown, in one or more embodiments of this application, step S102 may include the following steps S501-S503.

[0067] S501, if the target tracing type is program file tracing, then determine the application package corresponding to the network data to be traced.

[0068] Specifically, if the target tracing type is program file tracing, for example, the network data to be traced is itself an APK file or associated data of an APK file, then the application package corresponding to the traced network data can be determined, and the application package can be an APK file.

[0069] Optionally, the associated data for an APK file can be the hash value, signature, or download URL of the APK file.

[0070] S502, based on the tracing rules corresponding to the program file source, determines the communication domain name information, download link information, permission list information and sensitive word information corresponding to the application package in the multi-dimensional underlying database.

[0071] Specifically, based on the tracing rules corresponding to the program files and the correlation analysis between multidimensional Internet data, the communication domain name information, download link information, permission list information, and sensitive word information corresponding to the application package are determined in the multidimensional underlying data.

[0072] Optionally, all communication domains that have interactive behavior during the operation of the application package can be obtained from the multi-dimensional underlying database, and communication domain information can be generated based on the communication domains. The communication domain information may include the certificate fingerprint, creation time, etc. of the communication domain.

[0073] The download link corresponding to the application package can be obtained from the multidimensional underlying database, and download link information can be generated based on the download link. The download link information may include the URL of the download link, the download timestamp, the size of the downloaded file, etc.

[0074] It can retrieve all permissions declared in the application package from multi-dimensional underlying data and generate permission list information. It can also target sensitive words that appear after decompiling the application package, such as attack instructions appearing in the source code or string table.

[0075] S503 generates associated device information corresponding to the network data to be traced based on communication domain name information, download link information, permission list information, and sensitive word information.

[0076] Specifically, based on the obtained communication domain name information, download link information, permission list information, and sensitive word information, the terminal devices related to the network data to be traced are identified and associated device information is generated.

[0077] In this embodiment, if the target tracing type is program file tracing, the application package corresponding to the network data to be traced is determined. Based on the tracing rules corresponding to program file tracing, the communication domain name information, download link information, permission list information, and sensitive word information corresponding to the application package are determined in the multi-dimensional underlying database. Based on the communication domain name information, download link information, permission list information, and sensitive word information, the associated device information corresponding to the network data to be traced is generated. By performing tracing queries on the application package corresponding to the network data to be traced in the multi-dimensional underlying database, targeted tracing analysis for program file tracing types is achieved, improving the accuracy of tracing.

[0078] The associated device information refers to the device information of the terminal devices related to the network data to be traced. This information may include terminal configuration information, terminal files, software information, and network access records. Terminal configuration information can be the static parameters set by the terminal device at the factory or during initialization. Terminal files can be data stored locally on the terminal device, such as system files, download caches, and configuration files. Software information can be information about applications installed or running on the terminal device, such as the application name, version number, and installation time. Network access records can be the historical access records of the terminal device on the Internet, which may include the URLs accessed, the ports used, and the protocols used.

[0079] Please see Figure 7 This document provides a schematic diagram of the process for generating a result report, as illustrated in an embodiment of this application. Figure 7 As shown, in one or more embodiments of this application, step S103 may include the following steps S601-S603.

[0080] S601, based on the associated device information, performs profile characterization processing to generate a terminal profile corresponding to the network data to be traced.

[0081] Specifically, after obtaining the associated device information, a profile can be created based on the associated device information to generate a terminal profile corresponding to the network data to be traced. For example, the terminal profile can be used as a terminal device tag to describe the behavior of the terminal device, such as "fraudulent mobile phone located overseas" or "terminal using number spoofing software".

[0082] S602, based on the associated device information, performs source tracing and expansion processing to generate associated gang information and virtual identity information corresponding to the network data to be traced.

[0083] Specifically, the information of associated devices can be traced and expanded to obtain the associated gang information and virtual identity information corresponding to the network data to be traced in the multi-dimensional underlying database.

[0084] Optionally, the source tracing and expansion process may include gang discovery processing and alias tracking processing. Gang discovery processing may include terminal gang discovery, route gang discovery, and file gang discovery, thereby generating associated gang information. Alias ​​tracking processing may include virtual identity tracking processing, thereby determining the terminal access behavior and terminal access trajectory corresponding to the virtual identity, thereby generating virtual identity information.

[0085] S603 generates a source tracing result report corresponding to the network data to be traced, based on terminal profiles, associated gang information, and virtual identity information.

[0086] Specifically, the system aggregates terminal profiles, associated gang information, and virtual identity information to generate a tracing result report for the network data to be traced. For example, it can mark clues and key network data based on terminal profiles, associated gang information, and virtual identity information to depict the tracing route of the network data to be traced. The tracing result report can display all the information obtained in the aforementioned steps, such as associated device information, terminal profiles, associated gang information, and virtual identity information, as well as the obtained tracing route.

[0087] In this embodiment, a profiling process is performed based on associated device information to generate a terminal profile corresponding to the network data to be traced. Further tracing is then performed based on the associated device information to generate associated gang information and virtual identity information corresponding to the network data. Finally, a tracing result report is generated based on the terminal profile, associated gang information, and virtual identity information. Through profiling and tracing expansion, after obtaining relevant device information about the network to be traced, gang and virtual identity mining are further performed, and a displayable report is generated, improving the accuracy of the tracing analysis and the comprehensiveness of the tracing result report.

[0088] The following will be combined with the appendix Figure 8 -Appendix Figure 9 This application provides a detailed description of the traceability analysis device provided in its embodiments. It should be noted that the appendix... Figure 8 -Appendix Figure 9 The traceability analysis device in the present application is used to perform the traceability analysis. Figures 1-7 The methods shown in the embodiments are for illustrative purposes only, illustrating the parts relevant to the embodiments of this application. For specific technical details not disclosed, please refer to this application. Figures 1-7 The example shown.

[0089] Please see Figure 8 The diagram illustrates a structural schematic of a traceability analysis device provided in an exemplary embodiment of this application. This traceability analysis device can be implemented as all or part of a device through software, hardware, or a combination of both. The device 1 includes a traceability type determination unit 11, a multi-dimensional traceability unit 12, and a traceability analysis unit 13.

[0090] The source tracing type determination unit 11 is used to determine the target source tracing type corresponding to the network data to be traced. The multi-dimensional tracing unit 12 is used to perform multi-dimensional tracing processing based on the tracing rules corresponding to the target tracing type and the multi-dimensional underlying database, and to determine the associated device information corresponding to the network data to be traced. The traceability analysis unit 13 is used to perform traceability analysis processing based on the associated device information and generate a traceability result report corresponding to the network data to be traced.

[0091] In this embodiment, the target tracing type corresponding to the network data to be traced is determined. Multidimensional tracing processing is performed based on the tracing rules corresponding to the target tracing type and a multidimensional underlying database to determine the associated device information corresponding to the network data to be traced. Tracing analysis is then performed based on the associated device information to generate a tracing result report corresponding to the network data to be traced. By using the tracing type and combining it with the multidimensional underlying database to determine the associated device information, the response efficiency and accuracy of network data tracing are improved, and the generated result report facilitates the viewing and use of the tracing results by relevant personnel.

[0092] Please see Figure 9 This illustration shows a schematic diagram of the structure of a traceability analysis device provided in an exemplary embodiment of this application. The traceability analysis device can be implemented as all or part of a device through software, hardware, or a combination of both. The device 1 includes a database construction unit 14, a traceability type determination unit 11, a multi-dimensional traceability unit 12, and a traceability analysis unit 13.

[0093] Database construction unit 14 is used to collect multidimensional Internet data from data sources and perform data preprocessing on the multidimensional Internet data. The multidimensional Internet data after data preprocessing is subjected to correlation analysis to generate correlation analysis relationships between the multidimensional Internet data. Based on the multidimensional Internet data and the correlation analysis relationships, a multidimensional underlying database is constructed.

[0094] The source tracing type determination unit 11 is used to determine the target source tracing type corresponding to the network data to be traced. Optionally, the target tracing types include network address tracing, domain name tracing, and program file tracing.

[0095] The multi-dimensional tracing unit 12 is used to perform multi-dimensional tracing processing based on the tracing rules corresponding to the target tracing type and the multi-dimensional underlying database, and to determine the associated device information corresponding to the network data to be traced. Optionally, the multi-dimensional tracing unit 12 is specifically used to determine the target network address corresponding to the network data to be traced if the target tracing type is network address tracing. Based on the tracing rules corresponding to the network address, the associated terminal information, terminal access information, external connection behavior information and associated URL information of the target network address are determined in the multi-dimensional underlying database. Based on the associated terminal information, the terminal access information, the external connection behavior information, and the associated URL information, the associated device information corresponding to the network data to be traced is generated.

[0096] Optionally, the multi-dimensional tracing unit 12 is specifically used to determine the target domain name corresponding to the network data to be traced if the target tracing type is domain name tracing. Based on the tracing rules corresponding to the domain name, the access terminal information, terminal download information, associated domain name information and associated URL information corresponding to the target domain name are determined in the multi-dimensional underlying database; Based on the access terminal information, the terminal download information, the associated domain name information, and the associated URL information, the associated device information corresponding to the network data to be traced is generated.

[0097] Optionally, the multi-dimensional tracing unit 12 is specifically used to determine the application package corresponding to the network data to be traced if the target tracing type is program file tracing. Based on the tracing rules corresponding to the program file tracing, the communication domain name information, download link information, permission list information, and sensitive word information corresponding to the application package are determined in the multi-dimensional underlying database; Based on the communication domain name information, the download link information, the permission list information, and the sensitive word information, the associated device information corresponding to the network data to be traced is generated.

[0098] The traceability analysis unit 13 is used to perform traceability analysis processing based on the associated device information and generate a traceability result report corresponding to the network data to be traced.

[0099] Optionally, the source tracing analysis unit 13 is specifically used to perform profile characterization processing based on the associated device information to generate a terminal profile corresponding to the network data to be traced. Based on the associated device information, a source tracing and expansion process is performed to generate associated gang information and virtual identity information corresponding to the network data to be traced. Based on the terminal profile, the associated gang information, and the virtual identity information, a tracing result report corresponding to the network data to be traced is generated.

[0100] In this embodiment, multidimensional internet data is collected from a data source, preprocessed, and then subjected to correlation analysis to generate correlation relationships between the multidimensional internet data. Based on the multidimensional internet data and these correlation relationships, a multidimensional underlying database is constructed. By collecting big internet data and performing correlation analysis, a queryable multidimensional underlying database is built, improving the efficiency of subsequent multidimensional tracing and source tracing analysis. The target source tracing type corresponding to the network data to be traced is determined, including network address tracing, domain name tracing, and program file tracing.

[0101] If the target tracing type is network address tracing, then the target network address corresponding to the network data to be traced is determined. Based on the tracing rules corresponding to network address tracing, the associated terminal information, terminal access information, external connection behavior information, and associated URL information of the target network address are determined in the multi-dimensional underlying database. Based on the associated terminal information, terminal access information, external connection behavior information, and associated URL information, the associated device information corresponding to the network data to be traced is generated. If the target tracing type is domain name tracing, then the target domain name corresponding to the network data to be traced is determined. Based on the tracing rules corresponding to domain name tracing, the access terminal information, terminal download information, associated domain name information, and associated URL information corresponding to the target domain name are determined in the multi-dimensional underlying database. Based on the access terminal information, terminal download information, associated domain name information, and associated URL information, the associated device information corresponding to the network data to be traced is generated. If the target tracing type is program file tracing, the application package corresponding to the network data to be traced is determined. Based on the tracing rules corresponding to program file tracing, the communication domain name information, download link information, permission list information, and sensitive word information corresponding to the application package are determined in the multi-dimensional underlying database. Based on the communication domain name information, download link information, permission list information, and sensitive word information, the associated device information corresponding to the network data to be traced is generated. By performing tracing queries in the multi-dimensional underlying database according to the tracing type of the network data to be traced, targeted tracing analysis for program file tracing types is achieved, improving the accuracy of tracing. By determining the associated device information through the tracing type and the multi-dimensional underlying database, the response efficiency and accuracy of network data tracing are improved. Based on the associated device information, a profile is generated to produce a terminal profile corresponding to the network data to be traced. Based on the associated device information, tracing extension processing is performed to generate associated group information and virtual identity information corresponding to the network data to be traced. Based on the terminal profile, associated group information, and virtual identity information, a tracing result report corresponding to the network data to be traced is generated. By profiling and tracing the source, after obtaining relevant device information of the network to be traced, further investigation of gangs and virtual identities is conducted, and a report that can be displayed is generated. This improves the accuracy of the source tracing analysis, enhances the comprehensiveness of the source tracing results report, and facilitates relevant personnel to view and use the source tracing results.

[0102] It should be noted that the source tracing analysis device provided in the above embodiments is only illustrated by the division of the above functional modules when executing the source tracing analysis method. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the source tracing analysis device and the source tracing analysis method embodiments provided in the above embodiments belong to the same concept, and the implementation process is detailed in the method embodiments, which will not be repeated here.

[0103] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0104] This application also provides a computer storage medium that can store multiple instructions, which are adapted to be loaded and executed by a processor as described above. Figures 1-2 The source tracing analysis method described in the illustrated embodiment can be found in the following document for a detailed execution process: Figures 1-2 The specific details of the illustrated embodiments will not be elaborated here.

[0105] This application also provides a computer program product storing at least one instruction, which is loaded and executed by the processor as described above. Figures 1-2 The source tracing analysis method described in the illustrated embodiment can be found in the following document for a detailed execution process: Figures 1-2 The specific details of the illustrated embodiments will not be elaborated here.

[0106] Please refer to Figure 10 This diagram illustrates a structural block diagram of an electronic device provided in an exemplary embodiment of this application. The electronic device in this application may include one or more components such as a processor 110, a memory 120, an input device 130, an output device 140, and a bus 150. The processor 110, memory 120, input device 130, and output device 140 may be connected via the bus 150.

[0107] Processor 110 may include one or more processing cores. Processor 110 connects to various parts of the electronic device using various interfaces and lines, and executes various functions of terminal 100 and processes data by running or executing instructions, programs, code sets, or instruction sets stored in memory 120, and by calling data stored in memory 120. Optionally, processor 110 may be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). Processor 110 may integrate one or more of the following: Central Processing Unit (CPU), Graphics Processing Unit (GPU), and modem. The CPU primarily handles the operating system, user page, and applications; the GPU is responsible for rendering and drawing the displayed content; and the modem handles wireless communication. It is understood that the modem may also not be integrated into processor 110 and may be implemented separately using a communication chip.

[0108] The memory 120 may include random access memory (RAM) or read-only memory (ROM). Optionally, the memory 120 may include non-transitory computer-readable storage medium. The memory 120 may be used to store instructions, programs, code, code sets, or instruction sets. The memory 120 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for implementing at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the various method embodiments described above, etc. The operating system may be the Android system, including systems deeply developed based on the Android system, the iOS system developed by Apple Inc., including systems deeply developed based on the iOS system, or other systems.

[0109] The memory 120 can be divided into operating system space and user space. The operating system runs in the operating system space, while native and third-party applications run in user space. To ensure that different third-party applications can achieve good running performance, the operating system allocates corresponding system resources for each application. However, different application scenarios within the same third-party application have different requirements for system resources. For example, in local resource loading scenarios, third-party applications have high requirements for disk read speed; in animation rendering scenarios, third-party applications have high requirements for GPU performance. Since the operating system and third-party applications are independent of each other, the operating system often cannot promptly perceive the current application scenario of a third-party application, resulting in the operating system's inability to adapt system resources accordingly.

[0110] In order for the operating system to distinguish the specific application scenarios of third-party applications, it is necessary to establish data communication between the third-party applications and the operating system. This would allow the operating system to obtain the current scenario information of the third-party applications at any time, and then perform targeted system resource adaptation based on the current scenario.

[0111] The input device 130 is used to receive input instructions or data, and includes, but is not limited to, a keyboard, mouse, camera, microphone, or touch device. The output device 140 is used to output instructions or data, and includes, but is not limited to, a display device and a speaker. In one example, the input device 130 and the output device 140 can be combined, and the input device 130 and the output device 140 can be a touch display screen.

[0112] The touch display screen can be designed as a full-screen, curved screen, or irregularly shaped screen. It can also be designed as a combination of a full-screen and a curved screen, or a combination of an irregularly shaped screen and a curved screen; however, this application does not limit the specific design in this regard.

[0113] In addition, those skilled in the art will understand that the structure of the electronic device shown in the above figures does not constitute a limitation on the electronic device. The electronic device may include more or fewer components than shown, or combine certain components, or have different component arrangements. For example, the electronic device may also include radio frequency circuits, input units, sensors, audio circuits, Wireless Fidelity (WiFi) modules, power supplies, Bluetooth modules, etc., which will not be described in detail here.

[0114] exist Figure 10 In the illustrated electronic device, the processor 110 can be used to call the source tracing analysis application stored in the memory 120 and specifically perform the following operations: Determine the target tracing type corresponding to the network data to be traced; Based on the tracing rules corresponding to the target tracing type and the multi-dimensional underlying database, multi-dimensional tracing processing is performed to determine the associated device information corresponding to the network data to be traced. Based on the associated device information, a source tracing analysis is performed to generate a source tracing result report corresponding to the network data to be traced.

[0115] In one embodiment, before determining the target tracing type corresponding to the network data to be traced, the processor 110 also performs the following operations: Collect multidimensional Internet data from data sources and perform data preprocessing on the multidimensional Internet data; The multidimensional Internet data after data preprocessing is subjected to correlation analysis to generate correlation analysis relationships between the multidimensional Internet data. Based on the multidimensional Internet data and the correlation analysis relationships, a multidimensional underlying database is constructed.

[0116] In one embodiment, the target tracing type includes network address tracing, domain name tracing, and program file tracing.

[0117] In one embodiment, when the processor 110 performs multi-dimensional tracing processing based on the tracing rules corresponding to the target tracing type and the multi-dimensional underlying database to determine the associated device information corresponding to the network data to be traced, it specifically performs the following operations: If the target tracing type is network address tracing, then the target network address corresponding to the network data to be traced is determined; Based on the tracing rules corresponding to the network address, the associated terminal information, terminal access information, external connection behavior information and associated URL information of the target network address are determined in the multi-dimensional underlying database. Based on the associated terminal information, the terminal access information, the external connection behavior information, and the associated URL information, the associated device information corresponding to the network data to be traced is generated.

[0118] In one embodiment, when the processor 110 performs multi-dimensional tracing processing based on the tracing rules corresponding to the target tracing type and the multi-dimensional underlying database to determine the associated device information corresponding to the network data to be traced, it specifically performs the following operations: If the target tracing type is domain name tracing, then the target domain name corresponding to the network data to be traced is determined; Based on the tracing rules corresponding to the domain name, the access terminal information, terminal download information, associated domain name information and associated URL information corresponding to the target domain name are determined in the multi-dimensional underlying database; Based on the access terminal information, the terminal download information, the associated domain name information, and the associated URL information, the associated device information corresponding to the network data to be traced is generated.

[0119] In one embodiment, when the processor 110 performs multi-dimensional tracing processing based on the tracing rules corresponding to the target tracing type and the multi-dimensional underlying database to determine the associated device information corresponding to the network data to be traced, it specifically performs the following operations: If the target tracing type is program file tracing, then the application package corresponding to the network data to be traced is determined; Based on the tracing rules corresponding to the program file tracing, the communication domain name information, download link information, permission list information, and sensitive word information corresponding to the application package are determined in the multi-dimensional underlying database; Based on the communication domain name information, the download link information, the permission list information, and the sensitive word information, the associated device information corresponding to the network data to be traced is generated.

[0120] In one embodiment, when the processor 110 performs source tracing analysis based on the associated device information and generates a source tracing result report corresponding to the network data to be traced, it specifically performs the following operations: Based on the associated device information, a profile is created to generate a terminal profile corresponding to the network data to be traced. Based on the associated device information, a source tracing and expansion process is performed to generate associated gang information and virtual identity information corresponding to the network data to be traced. Based on the terminal profile, the associated gang information, and the virtual identity information, a tracing result report corresponding to the network data to be traced is generated.

[0121] In this embodiment, multidimensional internet data is collected from a data source, preprocessed, and then subjected to correlation analysis to generate correlation relationships between the multidimensional internet data. Based on the multidimensional internet data and these correlation relationships, a multidimensional underlying database is constructed. By collecting big internet data and performing correlation analysis, a queryable multidimensional underlying database is built, improving the efficiency of subsequent multidimensional tracing and source tracing analysis. The target source tracing type corresponding to the network data to be traced is determined, including network address tracing, domain name tracing, and program file tracing.

[0122] If the target tracing type is network address tracing, then the target network address corresponding to the network data to be traced is determined. Based on the tracing rules corresponding to network address tracing, the associated terminal information, terminal access information, external connection behavior information, and associated URL information of the target network address are determined in the multi-dimensional underlying database. Based on the associated terminal information, terminal access information, external connection behavior information, and associated URL information, the associated device information corresponding to the network data to be traced is generated. If the target tracing type is domain name tracing, then the target domain name corresponding to the network data to be traced is determined. Based on the tracing rules corresponding to domain name tracing, the access terminal information, terminal download information, associated domain name information, and associated URL information corresponding to the target domain name are determined in the multi-dimensional underlying database. Based on the access terminal information, terminal download information, associated domain name information, and associated URL information, the associated device information corresponding to the network data to be traced is generated. If the target tracing type is program file tracing, the application package corresponding to the network data to be traced is determined. Based on the tracing rules corresponding to program file tracing, the communication domain name information, download link information, permission list information, and sensitive word information corresponding to the application package are determined in the multi-dimensional underlying database. Based on the communication domain name information, download link information, permission list information, and sensitive word information, the associated device information corresponding to the network data to be traced is generated. By performing tracing queries in the multi-dimensional underlying database according to the tracing type of the network data to be traced, targeted tracing analysis for program file tracing types is achieved, improving the accuracy of tracing. By determining the associated device information through the tracing type and the multi-dimensional underlying database, the response efficiency and accuracy of network data tracing are improved. Based on the associated device information, a profile is generated to produce a terminal profile corresponding to the network data to be traced. Based on the associated device information, tracing extension processing is performed to generate associated group information and virtual identity information corresponding to the network data to be traced. Based on the terminal profile, associated group information, and virtual identity information, a tracing result report corresponding to the network data to be traced is generated. By profiling and tracing the source, after obtaining relevant device information of the network to be traced, further investigation of gangs and virtual identities is conducted, and a report that can be displayed is generated. This improves the accuracy of the source tracing analysis, enhances the comprehensiveness of the source tracing results report, and facilitates relevant personnel to view and use the source tracing results.

[0123] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. The storage medium can be a magnetic disk, optical disk, read-only memory, or random access memory, etc.

[0124] The above-disclosed embodiments are merely preferred embodiments of this application and should not be construed as limiting the scope of this application. Therefore, any equivalent variations made in accordance with the claims of this application shall still fall within the scope of this application.

[0125] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.), and signals involved in the embodiments of this specification are all authorized by the user or fully authorized by all parties, and the collection, use, and processing of related data must comply with the relevant laws, regulations, and standards of the relevant countries and regions. For example, the network data to be traced and the associated device information involved in this specification were obtained under full authorization.

Claims

1. A source tracing analysis method, characterized in that, The method includes: Determine the target tracing type corresponding to the network data to be traced; Based on the tracing rules corresponding to the target tracing type and the multi-dimensional underlying database, multi-dimensional tracing processing is performed to determine the associated device information corresponding to the network data to be traced. Based on the associated device information, a source tracing analysis is performed to generate a source tracing result report corresponding to the network data to be traced.

2. The method according to claim 1, characterized in that, Before determining the target tracing type corresponding to the network data to be traced, the process also includes: Collect multidimensional Internet data from data sources and perform data preprocessing on the multidimensional Internet data; The multidimensional Internet data after data preprocessing is subjected to correlation analysis to generate correlation analysis relationships between the multidimensional Internet data. Based on the multidimensional Internet data and the correlation analysis relationships, a multidimensional underlying database is constructed.

3. The method according to claim 1, characterized in that, The target tracing types include network address tracing, domain name tracing, and program file tracing.

4. The method according to claim 3, characterized in that, The multi-dimensional tracing process, based on the tracing rules corresponding to the target tracing type and a multi-dimensional underlying database, determines the associated device information corresponding to the network data to be traced, including: If the target tracing type is network address tracing, then the target network address corresponding to the network data to be traced is determined; Based on the tracing rules corresponding to the network address, the associated terminal information, terminal access information, external connection behavior information and associated URL information of the target network address are determined in the multi-dimensional underlying database. Based on the associated terminal information, the terminal access information, the external connection behavior information, and the associated URL information, the associated device information corresponding to the network data to be traced is generated.

5. The method according to claim 3, characterized in that, The multi-dimensional tracing process, based on the tracing rules corresponding to the target tracing type and a multi-dimensional underlying database, determines the associated device information corresponding to the network data to be traced, including: If the target tracing type is domain name tracing, then the target domain name corresponding to the network data to be traced is determined; Based on the tracing rules corresponding to the domain name, the access terminal information, terminal download information, associated domain name information and associated URL information corresponding to the target domain name are determined in the multi-dimensional underlying database; Based on the access terminal information, the terminal download information, the associated domain name information, and the associated URL information, the associated device information corresponding to the network data to be traced is generated.

6. The method according to claim 3, characterized in that, The multi-dimensional tracing process, based on the tracing rules corresponding to the target tracing type and a multi-dimensional underlying database, determines the associated device information corresponding to the network data to be traced, including: If the target tracing type is program file tracing, then the application package corresponding to the network data to be traced is determined; Based on the tracing rules corresponding to the program file tracing, the communication domain name information, download link information, permission list information, and sensitive word information corresponding to the application package are determined in the multi-dimensional underlying database; Based on the communication domain name information, the download link information, the permission list information, and the sensitive word information, the associated device information corresponding to the network data to be traced is generated.

7. The method according to claim 1, characterized in that, The process of performing source tracing analysis based on the associated device information to generate a source tracing result report corresponding to the network data to be traced includes: Based on the associated device information, a profile is created to generate a terminal profile corresponding to the network data to be traced. Based on the associated device information, a source tracing and expansion process is performed to generate associated gang information and virtual identity information corresponding to the network data to be traced. Based on the terminal profile, the associated gang information, and the virtual identity information, a tracing result report corresponding to the network data to be traced is generated.

8. A source tracing analysis device, characterized in that, The device includes: The source tracing type determination unit is used to determine the target source tracing type corresponding to the network data to be traced. The multi-dimensional tracing unit is used to perform multi-dimensional tracing processing based on the tracing rules corresponding to the target tracing type and the multi-dimensional underlying database, and to determine the associated device information corresponding to the network data to be traced. The source tracing analysis unit is used to perform source tracing analysis based on the associated device information and generate a source tracing result report corresponding to the network data to be traced.

9. A computer storage medium, characterized in that, The computer storage medium stores a plurality of instructions, which are adapted to be loaded by a processor and executed as method steps as claimed in any one of claims 1 to 7.

10. An electronic device, characterized in that, include: A processor and a memory; wherein the memory stores a computer program adapted to be loaded by the processor and executed the method steps as claimed in any one of claims 1 to 7.

Citation Information

Cited By

  • A mobile application research and judgment method and system

    CN122294117A