Application behavior security testing methods, devices, equipment, media and program products
By collecting sensitive behavioral data of banking applications in real time within the trusted execution environment of a secure chip on the terminal device, and combining this data with historical usage data for risk analysis and anomaly verification, the problem of low security in application behavior detection in existing technologies is solved, achieving higher detection security and privacy protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- INDUSTRIAL AND COMMERCIAL BANK OF CHINA
- Filing Date
- 2026-01-28
- Publication Date
- 2026-06-02
AI Technical Summary
In existing technologies, application behavior security detection methods suffer from several problems when facing malware attacks, including difficulty in balancing privacy protection and functional integrity, a significant conflict between performance consumption and device compatibility, and weak system-level attack defense capabilities, resulting in low detection security.
In the trusted execution environment of the security chip of the terminal device under test, sensitive behavioral data of banking applications are collected in real time. Risk analysis is performed by combining historical usage data to generate a security report. Abnormal behavior is verified in the trusted execution environment, and the report is displayed after anonymization.
It improves the security of application behavior detection, ensures the safety and reliability of the data collection environment, accurately identifies risk categories, enhances the accuracy of risk assessment, and provides detection results while protecting user privacy.
Smart Images

Figure CN122134445A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of financial technology, and in particular to a method, apparatus, device, medium, and program product for security detection of application behavior. Background Technology
[0002] In today's society, where finance and technology are highly integrated, users rely on mobile banking applications for daily financial transactions. When a user's mobile device is hijacked due to malware or system vulnerabilities, the banking application, operating in an insecure environment, may face abnormal and unauthorized access to sensitive permissions. This is a core root cause of financial risks such as account information leaks and fund theft. Therefore, developing a security detection method that can effectively identify abnormal application behavior caused by device hijacking has become a promising application direction.
[0003] In existing technologies, application behavior security detection methods mainly employ cloud-based analysis and local detection models. The former uploads application behavior data to a remote server and uses a centralized analysis system for risk assessment; the latter deploys a detection program based on a static rule base on the device side to intercept risks by scanning application operations in real time.
[0004] However, in existing technical solutions, uploading sensitive data in the cloud mode can easily lead to privacy leaks, and local static rules are difficult to cope with complex scenarios and are easily shut down or tampered with by malware. Ultimately, the protection measures may fail when faced with actual threats. This results in technical solutions having defects such as difficulty in balancing privacy protection and functional integrity, prominent contradictions between performance consumption and device compatibility, and weak system-level attack defense capabilities. Consequently, existing technologies have technical problems with low security in detecting application behavior. Summary of the Invention
[0005] This application provides a method, apparatus, device, medium, and program product for detecting the security of application behavior, in order to solve the technical problem of low security in the existing technology for detecting application behavior.
[0006] Firstly, this application provides a method for security detection of application behavior, comprising:
[0007] Based on the startup status of the banking applications installed on the terminal device under test, sensitive behavioral data of the banking applications are collected in real time within the trusted execution environment corresponding to the security chip of the terminal device under test.
[0008] In a trusted execution environment, risk analysis is performed on sensitive behavioral data based on the historical usage data of the banking applications corresponding to the terminal devices under test, in order to determine the risk category of the sensitive behavioral data.
[0009] Based on the risk category, generate a security report for the banking application and display a prompt indicating the security report has been generated;
[0010] In response to user requests to view security report generation prompts, abnormal behavior verification is performed on the terminal devices and banking applications under test in a trusted execution environment.
[0011] If the abnormal behavior verification is passed, the security report will be anonymized to obtain an anonymized security report.
[0012] Display the desensitization safety report.
[0013] Secondly, this application provides a security detection device for application behavior, comprising:
[0014] The first acquisition module is used to collect sensitive behavioral data of the banking application in real time in the trusted execution environment corresponding to the security chip of the terminal device under test, based on the startup status of the banking application installed in the terminal device under test.
[0015] The risk analysis module is used in a trusted execution environment to perform risk analysis on sensitive behavioral data based on the historical usage data of the banking applications corresponding to the terminal devices under test, so as to determine the risk category of the sensitive behavioral data.
[0016] The report processing module is used to generate security reports for banking applications based on risk categories and display security report generation prompts;
[0017] The verification module is used to respond to the user's viewing operation of the security report generation prompts and to verify abnormal behavior of the terminal device and banking application to be tested in a trusted execution environment.
[0018] The desensitization module is used to desensitize the security report if the abnormal behavior verification is passed, so as to obtain a desensitized security report.
[0019] The display module is used to display the desensitization security report.
[0020] Thirdly, embodiments of this application provide an electronic device, including: a memory and a processor;
[0021] The memory stores instructions that the computer executes;
[0022] The processor executes computer execution instructions stored in memory, causing the processor to perform the method described in the first aspect above.
[0023] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the method described in the first aspect above.
[0024] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the method described in the first aspect above.
[0025] This application provides a method, apparatus, device, medium, and program product for security detection of application behavior. By collecting sensitive behavioral data in real time based on the startup status of banking applications within the trusted execution environment of the security chip of the terminal device under test, it ensures a secure and reliable data collection environment, preventing data theft or tampering. Utilizing historical usage data of the device in a trusted environment to analyze risks allows for accurate identification of risk categories, improving the accuracy of risk assessment. A security report is generated based on the risk category and displayed to the user, keeping them informed of the application's security status. The response viewing operation verifies abnormal behavior in a trusted environment, further ensuring detection security. After successful anomaly verification, the report is anonymized to protect user privacy. Finally, the anonymized report is displayed, allowing users to understand the application behavior detection results securely and with privacy protected, thus achieving the overall technical effect of improving the security of application behavior detection. Attached Figure Description
[0026] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0027] Figure 1 This application provides a schematic diagram of an application data processing system architecture.
[0028] Figure 2 A flowchart illustrating a security detection method for application behavior provided in this application embodiment. Figure 1 ;
[0029] Figure 3 A flowchart illustrating a security detection method for application behavior provided in this application embodiment. Figure 2 ;
[0030] Figure 4 A flowchart illustrating a security detection method for application behavior provided in this application embodiment. Figure 3 ;
[0031] Figure 5 A flowchart illustrating a security detection method for application behavior provided in this application embodiment. Figure 4 ;
[0032] Figure 6 A flowchart illustrating a security detection method for application behavior provided in this application embodiment. Figure 5 ;
[0033] Figure 7A flowchart illustrating a security detection method for application behavior provided in this application embodiment. Figure 6 ;
[0034] Figure 8 A schematic diagram of the structure of a security detection device for application behavior provided in an embodiment of this application;
[0035] Figure 9 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.
[0036] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0037] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0038] It should be noted that the user information (including but not limited to user device information, user personal information, user financial characteristics information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, data used for scoring, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of the relevant data all comply with the relevant laws, regulations, and standards of the relevant countries and regions, have taken necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation portals for users to choose to authorize or refuse.
[0039] It should be noted that the application behavior security detection methods, devices, equipment, media and program products provided in this application can be used in the financial technology field, or in any field other than financial technology. The application fields of the application behavior security detection methods, devices, equipment, storage media and products in this application are not limited.
[0040] Because existing technical solutions are prone to privacy leaks when uploading sensitive data in the cloud, and local static rules are difficult to cope with complex scenarios and are easily shut down or tampered with by malware, the protection measures may fail when faced with actual threats. This results in technical solutions having defects such as difficulty in balancing privacy protection and functional integrity, prominent contradictions between performance consumption and device compatibility, and weak system-level attack defense capabilities. Consequently, existing technologies have low security for detecting application behavior.
[0041] To address the aforementioned issues, this application provides a method, apparatus, device, medium, and program product for security detection of application behavior. By collecting sensitive behavioral data in real-time within the trusted execution environment of the security chip on the terminal device under test, based on the startup status of the banking application, the data collection environment is guaranteed to be secure and reliable, preventing data theft or tampering. Utilizing historical usage data of the device in a trusted environment to analyze risks allows for accurate identification of risk categories, improving the accuracy of risk assessment. A security report is generated based on the risk category and displayed to the user, ensuring timely awareness of the application's security status. The response viewing operation verifies abnormal behavior in a trusted environment, further guaranteeing detection security. After successful anomaly verification, the report is anonymized to protect user privacy. Finally, the anonymized report is displayed, allowing users to understand the application behavior detection results securely and with privacy protected, thus achieving the overall technical effect of improving the security of application behavior detection.
[0042] Figure 1 This is a schematic diagram of an application data processing system architecture provided in an embodiment of this application. The application data processing system can be a computer device. Figure 1 As shown, the above architecture includes at least one of a data acquisition device 101, a processing device 102, and a display device 103.
[0043] It is understood that the structures illustrated in the embodiments of this application do not constitute a specific limitation on the architecture of the application data processing system. In other feasible embodiments of this application, the above architecture may include more or fewer components than illustrated, or combine some components, or split some components, or arrange different components, which can be determined according to the actual application scenario and is not limited here. Figure 1 The components shown can be implemented in hardware, software, or a combination of both.
[0044] In the specific implementation process, the data acquisition device 101 may include an input / output interface or a communication interface, and the data acquisition device 101 can be connected to the processing device through the input / output interface or the communication interface.
[0045] The processing device 102 can collect sensitive behavior data in real time according to the startup status of the bank application in the trusted execution environment of the security chip of the terminal device under test. Then, it analyzes the risk category in the environment in combination with the historical usage data of the device, generates a security report and prompts the user to view it. When the user views it, the abnormal behavior is verified in the trusted environment. After the verification is passed, the report is desensitized and finally the desensitized report is displayed, thereby improving the security of application behavior detection.
[0046] The display device 103 can also be a touch screen or the screen of a terminal device, used to receive user commands while displaying the above-mentioned content, so as to realize interaction with the user.
[0047] It should be understood that the aforementioned processing device can be implemented by a processor reading instructions from memory and executing those instructions, or it can be implemented by a chip circuit.
[0048] Furthermore, the network architecture and business scenarios described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0049] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.
[0050] Figure 2 A flowchart illustrating a security detection method for application behavior provided in this application embodiment. Figure 1 ,like Figure 2 As shown in the embodiments of this application, the application behavior security detection method includes:
[0051] S201. Based on the startup status of the banking application installed in the terminal device under test, sensitive behavioral data of the banking application are collected in real time within the trusted execution environment corresponding to the security chip of the terminal device under test.
[0052] When the terminal device under test starts the banking application, the Trusted Execution Environment (TEE) corresponding to the security chip is used to automatically collect sensitive behavioral data of the banking application in real time through physically isolated hardware channels, such as reading the address book and calling the camera, to ensure that the main system and other software cannot touch or tamper with the original records, thus ensuring the security of data collection.
[0053] S202. In a trusted execution environment, based on the historical usage data of the banking application corresponding to the terminal device under test, risk analysis processing is performed on the sensitive behavioral data to determine the risk category of the sensitive behavioral data.
[0054] In one possible implementation, the historical usage data of the banking application includes multiple factors such as the user's usage habits corresponding to the historical usage behavior of the banking application, the time when the behavior occurred, and the current state of the device.
[0055] In a trusted execution environment, the risk of sensitive behavioral data is dynamically assessed by combining historical usage data of the banking applications corresponding to the terminal devices under test, including user habits, time of occurrence of behavior, and current status of the device, in order to determine its risk category.
[0056] S203. Generate a security report for the banking application based on the risk category and display a prompt indicating that a security report has been generated.
[0057] Based on the identified risk categories, a security report is generated for banking applications in a secure environment. The report includes information such as the risk situation and displays a security report generation prompt on the terminal device to inform the user of the detection results.
[0058] S204. In response to the user's viewing operation of the security report generation prompt, perform abnormal behavior verification on the terminal device and banking application to be tested in a trusted execution environment.
[0059] In one possible implementation, verifying abnormal behavior of the terminal device to be detected and the banking application includes at least one of the following:
[0060] Verify whether the banking application has been maliciously modified based on its initial and current digital fingerprints.
[0061] The file information of the terminal device under test is detected to verify whether the terminal device under test has been illegally hacked based on the file information;
[0062] The system detects forced shutdown operations on the terminal device under test, collects shutdown information based on the forced shutdown operations, and verifies whether there is an abnormal shutdown phenomenon on the terminal device under test based on the shutdown information.
[0063] When a user responds to a security report prompt and attempts to view it, anomaly verification of the tested terminal device and banking application is initiated within a trusted execution environment. First, the system checks whether the banking application has been maliciously modified, comparing the initial digital fingerprint from when the application was first installed with the current digital fingerprint verified upon startup, including parameters such as file size and creation time. Any discrepancies are flagged as an anomaly. Next, the system checks whether the tested terminal device has been illegally hacked, detecting traces of root access and residual files from system permission breaching tools. If a forced shutdown occurs during operation, shutdown information is collected, and the system status and program execution before and after shutdown are used to determine if an abnormal shutdown occurred. A security prompt is displayed if verification passes; otherwise, an alert is triggered.
[0064] S205. If the abnormal behavior verification passes, the security report will be desensitized to obtain a desensitized security report.
[0065] If the abnormal behavior verification passes all verifications, indicating that the device is in a safe state, the security report will be anonymized. This involves overwriting the original behavior record with scrambled text, followed by a chip-level power outage to completely erase all traces, retaining only the anonymized behavior type label to prevent the leakage of user privacy information.
[0066] S206, Display the desensitization safety report.
[0067] In one possible implementation, after displaying the de-identified security report, the method further includes: in response to the user's evidence storage operation, storing the de-identified security report in segments.
[0068] After the anonymization process is completed, the anonymized security report is displayed on the terminal device interface. Users can view the report by opening the relevant application in the security center. The report presents warning items in a visual format. When the user clicks the "Store Evidence" button on the report page, the key features of the report are compressed into digital fragments and stored in a distributed manner via WiFi connection to surrounding devices. Successful evidence storage displays fragment hosting information and generates a unique QR code.
[0069] This embodiment provides a method for security detection of application behavior. By collecting sensitive behavioral data in real time based on the startup status of banking applications within the trusted execution environment of the security chip of the terminal device under test, the method ensures the security and reliability of the data collection environment, preventing data theft or tampering. Analyzing risks using historical usage data of the device in the trusted environment allows for accurate identification of risk categories, improving the accuracy of risk assessment. A security report is generated based on the risk category and displayed to the user, keeping them informed of the application's security status. The response viewing operation verifies abnormal behavior in the trusted environment, further ensuring detection security. After successful anomaly verification, the report is anonymized to protect user privacy. Finally, the anonymized report is displayed, allowing users to understand the application behavior detection results in a secure and privacy-protected manner, thus achieving the overall technical effect of improving the security of application behavior detection.
[0070] Optional, Figure 3 A flowchart illustrating a security detection method for application behavior provided in this application embodiment. Figure 2 ,like Figure 3 As shown, this embodiment, based on the above embodiments, provides a detailed explanation of the process for determining the risk category of sensitive behavioral data, including:
[0071] S301. Cross-compare data based on historical usage habits and sensitive behavior data of bank applications.
[0072] Sensitive behavioral data is obtained from the trusted execution environment corresponding to the security chip of the terminal device under test, while simultaneously retrieving stored historical usage data of banking applications. This historical usage data covers user habits, such as frequently used applications, usage periods, the time of occurrence of the behavior, and the current device status. This sensitive behavioral data is then compared with the historical usage data of banking applications according to key elements such as behavior type and time dimension, analyzing the similarities and differences between the two in terms of behavioral patterns, frequency, and time distribution.
[0073] S302. Based on the cross-comparison results, determine the risk category of sensitive behavioral data.
[0074] Based on the results of cross-comparison, if the sensitive behavioral data is highly consistent with the historical usage data of the bank application and there are no abnormal changes in time or frequency, it is judged as a low-risk category; if there are some deviations, such as slightly higher frequency but in accordance with certain logic, it is judged as a medium-risk category; if the behavioral patterns, time, frequency, etc. of the sensitive behavioral data are significantly different from the historical usage data of the bank application, or if there are unusual behaviors, it is judged as a high-risk category.
[0075] This embodiment provides a security detection method for application behavior. By cross-referencing sensitive behavioral data with historical usage data of bank applications, it can accurately capture behavioral differences and provide a comprehensive basis for risk assessment. Based on the comparison results, risk categories are determined, and low, medium, and high-risk behaviors can be quickly distinguished, allowing the system to be aware of the potential threat level in a timely manner so as to take targeted measures to ensure the safe operation of equipment.
[0076] Optional, Figure 4 A flowchart illustrating a security detection method for application behavior provided in this application embodiment. Figure 3 ,like Figure 4 As shown, this embodiment, based on the above embodiments, provides a supplementary explanation of another process for determining the risk category of sensitive behavioral data, including:
[0077] S401. Based on the historical usage data of bank applications and the corresponding risk tags, train the initial risk category identification model to obtain the trained risk category identification model.
[0078] The process involves collecting historical usage data of banking applications, including users' past activity records. Each piece of historical usage data is then labeled with a corresponding risk tag, determined based on factors such as whether the behavior is compliant and whether it may compromise privacy. This tagged historical usage data is then used to repeatedly train an initial risk category identification model, continuously adjusting the model parameters to allow the model to learn the correlation between different behaviors and risk tags, ultimately resulting in a well-trained risk category identification model.
[0079] The specific training process can be as follows: First, collect massive amounts of historical habit data, covering user operations on banking applications in different scenarios, such as abnormal access to the address book. Simultaneously, label each data point with a risk tag according to preset standards, clearly defining its risk level as low, medium, or high. Next, divide the data into training, validation, and test sets. Input the training set data into the initial risk category recognition model. The model extracts features from the input data, analyzing the correlation between behavioral patterns, frequencies, and other features and risk tags. Continuously adjust model parameters, such as weights and biases, using the backpropagation algorithm to gradually reduce the error between the model's predictions and the true labels. During training, evaluate the model's performance using the validation set. If the performance is unsatisfactory, adjust the hyperparameters and continue training until the model performs stably on the validation set. Finally, use the test set to test the model's generalization ability, resulting in a well-trained risk category recognition model.
[0080] S402. Based on the trained risk category identification model, perform risk identification processing on the sensitive behavior data to obtain the risk category of the sensitive behavior data.
[0081] Sensitive behavior data obtained from the trusted execution environment is input into a trained risk category identification model. Based on learned patterns, the risk category identification model analyzes and processes the input sensitive behavior data to determine which risk category the behavior belongs to, such as low risk, medium risk, or high risk, thereby obtaining the risk category of the sensitive behavior data.
[0082] This embodiment provides a security detection method for application behavior. It trains an initial risk category identification model using a large amount of tagged historical usage data of banking applications. This model accurately grasps the correspondence between behavior and risk, improving the accuracy of risk assessment. By using the trained risk category identification model to identify risks in sensitive behavioral data, the risk category of sensitive behavioral data can be quickly and efficiently determined, providing a reliable basis for subsequent security measures and ensuring the secure operation of terminal devices.
[0083] Optional, Figure 5 A flowchart illustrating a security detection method for application behavior provided in this application embodiment. Figure 4 ,like Figure 5 As shown, this embodiment, based on the above embodiments, provides a detailed description of the process for collecting sensitive behavioral data, including:
[0084] S501. After confirming that the banking application has started, establish a data transmission channel between the banking application and the trusted execution environment corresponding to the security chip of the terminal device under test.
[0085] When the banking application starts, the system establishes a physically isolated data transmission channel between the banking application and the trusted execution environment corresponding to the security chip through a hardware-level triggering mechanism. This channel generates a unique key pair based on the hardware encryption module of the security chip to perform end-to-end encryption on the transmitted data, ensuring that the main system and other applications cannot intercept or tamper with the data stream within the channel. At the same time, the channel has real-time bandwidth allocation capabilities, which can dynamically adjust the transmission rate according to the frequency of the banking application's behavior, avoiding delays in behavior monitoring due to data congestion.
[0086] S502, the Trusted Execution Environment monitors the application behavior of banking applications installed on the terminal device under test in real time through the data transmission channel.
[0087] The trusted execution environment continuously reads the process status, application programming interface (API) call records, and system resource usage data of the banking application at a millisecond-level sampling frequency through the established data transmission channel. The monitoring scope covers the application's foreground running, background resident, and hibernation states. The occurrence time of each behavioral event is marked with hardware-level timestamps to ensure the temporal continuity of the behavioral sequence. At the same time, abnormal behaviors (such as frequent wake-ups and unauthorized memory access) are marked in real time and temporarily stored in an encrypted buffer.
[0088] S503. In a trusted execution environment, sensitive behavior identification and processing are performed on application behavior based on preset sensitive behavior information.
[0089] In a trusted execution environment, based on pre-defined sensitive behavior information—which explicitly defines which behaviors fall under the sensitive category, such as reading specific files—a checklist is used to compare and analyze each monitored application behavior to determine whether it qualifies as a sensitive action.
[0090] S504. If the application behavior is identified as a sensitive behavior, the corresponding sensitive behavior data will be collected.
[0091] When an application's behavior is identified as matching preset sensitive behavior characteristics, a data collection mechanism is immediately initiated. Through the aforementioned data transmission channels, sensitive behavior data corresponding to that behavior is accurately collected, including detailed information such as the time of occurrence, the target of the action, and the frequency.
[0092] This embodiment provides a security detection method for application behavior. By monitoring the application behavior of banking applications in real time, it can comprehensively grasp the operational dynamics of banking applications on the device, providing a foundation for subsequent identification of sensitive behaviors. Sensitive behaviors are accurately identified based on preset information, avoiding omissions or misjudgments and improving identification accuracy. Timely collection of sensitive behavior data provides detailed evidence for subsequent risk assessment and security protection, ensuring the security of terminal devices.
[0093] Optional, Figure 6 A flowchart illustrating a security detection method for application behavior provided in this application embodiment. Figure 5 ,like Figure 6 As shown, this embodiment, based on the above embodiments, provides a detailed explanation of the process for obtaining the desensitized security report, including:
[0094] S601. Identify sensitive information in sensitive behavioral data.
[0095] In a trusted execution environment, the collected sensitive behavior data is analyzed in detail. Based on a pre-defined sensitive information rule base, the rule base clearly defines the characteristics of various key information that may involve user privacy and security, such as specific contact information and precise geographical coordinates, and accurately identifies the sensitive information in them.
[0096] S602. Desensitize the sensitive information to obtain the desensitized sensitive information.
[0097] By employing specific desensitization algorithms, such as replacing key characters in sensitive information with randomly generated garbled characters, or encrypting and encoding sensitive information, the identified sensitive information is transformed into a form that cannot be directly recognized from its original content, thus obtaining desensitized sensitive information.
[0098] S603. Overwrite the sensitive behavioral data with the desensitized sensitive information to obtain the desensitized behavioral data.
[0099] The desensitized sensitive information is accurately overlaid into the corresponding position in the sensitive behavioral data, replacing the original sensitive information, thus obtaining desensitized behavioral data that does not contain the original sensitive content but only retains the desensitized information.
[0100] S604. Generate a desensitization safety report based on the desensitized behavioral data and risk categories.
[0101] In one possible implementation, an invisible anti-counterfeiting dot matrix is added to the desensitized security report.
[0102] Based on the anonymized behavioral data and the risk categories determined in the above embodiments, the anonymized behavioral data and risk category information are accurately filled into the corresponding positions in the preset report template. During the filling process, for cases where invisible anti-counterfeiting dots need to be added, a specific encoding algorithm is used to generate invisible anti-counterfeiting dots that are not visible to the naked eye but can be identified by specific devices or software in specific areas of the report (such as headers, footers, or blank spaces in the body text). These dots contain key information such as the report's unique identifier and generation time. After completing the filling and adding of the anti-counterfeiting dots, an anonymized security report containing necessary information, without disclosing the original sensitive content, and with invisible anti-counterfeiting markings is generated, ensuring the report's authenticity and traceability.
[0103] This embodiment provides a security detection method for application behavior. By accurately identifying sensitive information, it provides a clear target for subsequent de-identification processing, avoiding the omission of key privacy content. De-identification of sensitive information effectively protects user privacy and prevents information leakage. Obtaining de-identified behavioral data ensures data usability while eliminating privacy risks. A de-identified security report is generated, providing users with clear risk information, and the addition of invisible anti-counterfeiting dots ensures the report's authenticity and credibility.
[0104] Optional, Figure 7 A flowchart illustrating a security detection method for application behavior provided in this application embodiment. Figure 6 ,like Figure 7 As shown, this embodiment, based on the above embodiments, provides a detailed description of the subsequent process after determining the risk category of sensitive behavioral data, including:
[0105] S701. If the risk category is high risk, a risk pop-up window will be displayed on the terminal device to be tested.
[0106] In this embodiment, the risk pop-up includes a block selection area and a temporarily unprocessed selection area.
[0107] After determining the risk category of sensitive behavioral data, if it is judged to be high-risk, the system will immediately display a risk pop-up window on the screen of the terminal device being monitored. This pop-up window contains two clearly defined selection areas: a block selection area and a temporary non-action selection area. The block selection area is used by the user to choose to immediately block the high-risk behavior; the temporary non-action selection area is for the user to choose if they do not want to deal with the risky behavior at the moment, giving the user flexible time to handle it.
[0108] S702, In response to the user's selection operation in the blocking selection area, perform risk protection processing.
[0109] In this embodiment, the risk protection process includes generating interference information and / or blocking power supply.
[0110] Once the user selects the area to block in the risk pop-up window and confirms the operation, the system will respond quickly and execute risk protection measures. These measures are diverse, including generating interference information to disrupt the normal execution of sensitive behaviors, preventing them from obtaining accurate data; or directly cutting off the power supply to the sensitive behaviors, forcibly terminating their operation, thereby effectively reducing the potential harm of high-risk behaviors to terminal devices and users.
[0111] This embodiment provides a method for detecting the security of application behavior. By displaying a risk pop-up window, it clearly informs the user of high-risk situations and provides processing options, allowing the user to be aware of and participate in risk response in a timely manner, thus enhancing the user's sense of control over device security. Responding to the user's choice to execute risk protection actions, such as generating interference information or blocking power supply, can effectively prevent high-risk behaviors from continuing to harm the terminal device, ensuring the safe and stable operation of the device, reducing risks such as user privacy leaks, and further improving the security of application behavior detection.
[0112] Figure 8 This is a schematic diagram of a security detection device for application behavior provided in an embodiment of this application. The device in this embodiment can be in the form of software and / or hardware. Figure 8As shown in the embodiment of this application, a security detection device 800 for application behavior is provided. The device includes: a first acquisition module 801, a risk analysis module 802, a report processing module 803, a verification module 804, a desensitization processing module 805, and a display module 806.
[0113] The first acquisition module 801 is used to collect sensitive behavior data of the banking application in real time in the trusted execution environment corresponding to the security chip of the terminal device under test, based on the startup status of the banking application installed in the terminal device under test.
[0114] Risk analysis module 802 is used in a trusted execution environment to perform risk analysis on sensitive behavioral data based on the historical usage data of the bank application corresponding to the terminal device under test, so as to determine the risk category of the sensitive behavioral data.
[0115] The report processing module 803 is used to generate security reports for banking applications based on risk categories and display security report generation prompts;
[0116] The verification module 804 is used to verify abnormal behavior of the terminal device and banking application to be tested in a trusted execution environment in response to the user's viewing operation of the security report generation prompt.
[0117] The desensitization module 805 is used to desensitize the security report if the abnormal behavior verification is passed, so as to obtain a desensitized security report.
[0118] Display module 806 is used to display the desensitization security report.
[0119] In one possible implementation, the risk analysis module 802 is also used for bank application historical usage data, which includes multiple factors such as user habits, the time of occurrence of the behavior, and the current state of the device corresponding to the bank application's historical usage behavior.
[0120] In one possible implementation, the risk analysis module 802 is further configured to:
[0121] Cross-comparison processing was performed based on historical usage data and sensitive behavior data of bank applications;
[0122] Based on the cross-comparison results, the risk category of sensitive behavioral data is determined.
[0123] In one possible implementation, the risk analysis module 802 is further configured to:
[0124] Based on historical usage data of bank applications and the corresponding risk tags, the initial risk category identification model is trained to obtain a trained risk category identification model.
[0125] Based on the trained risk category identification model, risk identification processing is performed on sensitive behavior data to obtain the risk category of the sensitive behavior data.
[0126] In one possible implementation, the verification module 804 is further used for at least one of the following:
[0127] Verify whether the banking application has been maliciously modified based on its initial and current digital fingerprints.
[0128] The file information of the terminal device under test is detected to verify whether the terminal device under test has been illegally hacked based on the file information;
[0129] The system detects forced shutdown operations on the terminal device under test, collects shutdown information based on the forced shutdown operations, and verifies whether there is an abnormal shutdown phenomenon on the terminal device under test based on the shutdown information.
[0130] In one possible implementation, the first acquisition module 801 is further configured to:
[0131] After confirming the startup of the banking application, a data transmission channel is established between the banking application and the trusted execution environment corresponding to the security chip of the terminal device under test;
[0132] The Trusted Execution Environment monitors the application behavior of banking applications installed on the terminal devices under test in real time through the data transmission channel;
[0133] In a trusted execution environment, sensitive behavior identification and processing are performed on application behaviors based on preset sensitive behavior information;
[0134] If an application behavior is identified as a sensitive behavior, then sensitive behavior data will be collected.
[0135] In one possible implementation, the desensitization processing module 805 is further configured to:
[0136] Identify sensitive information within sensitive behavioral data;
[0137] Sensitive information is de-identified to obtain the de-identified sensitive information;
[0138] The sensitive information after desensitization is overlaid on the sensitive behavioral data to obtain the desensitized behavioral data;
[0139] A desensitization safety report is generated based on the desensitized behavioral data and risk categories.
[0140] In one possible implementation, the desensitization processing module 805 is also used for desensitization security reports, in which invisible anti-counterfeiting dot matrix is added.
[0141] In one possible implementation, the display module 806 is further configured to:
[0142] In response to the user's evidence storage operation, the de-identified security report is stored in segments.
[0143] In one possible implementation, the risk analysis module 802 is further configured to:
[0144] If the risk category is high risk, a risk pop-up window will be displayed on the terminal device to be tested; the risk pop-up window includes a blocking selection area and a temporary non-processing selection area.
[0145] In response to the user's selection of the blocking selection area, risk protection processing is performed; wherein, risk protection processing includes generating interference information and / or blocking power supply.
[0146] This embodiment provides a security detection device for application behavior, which can execute the method provided in the above-described method embodiment. Its implementation principle and technical effect are similar, and will not be described in detail here.
[0147] Figure 9 This is a schematic diagram of the structure of an electronic device provided in this application. Figure 9 As shown, the electronic device 900 provided in this embodiment includes at least one processor 901 and a memory 902. Optionally, the device 900 further includes a communication component 903. The processor 901, memory 902, and communication component 903 are connected via a bus.
[0148] In a specific implementation, at least one processor 901 executes computer execution instructions stored in memory 902, causing at least one processor 901 to perform the above-described method.
[0149] The specific implementation process of processor 901 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.
[0150] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.
[0151] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.
[0152] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.
[0153] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.
[0154] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the above-described method.
[0155] The aforementioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.
[0156] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the device.
[0157] The division of units is merely a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.
[0158] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0159] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0160] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0161] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.
[0162] Finally, it should be noted that other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein, and is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.
Claims
1. A method for security detection of application behavior, characterized in that, include: Based on the startup status of the banking application installed in the terminal device under test, sensitive behavior data of the banking application is collected in real time in the trusted execution environment corresponding to the security chip of the terminal device under test. In the trusted execution environment, risk analysis processing is performed on the sensitive behavior data based on the historical usage data of the bank application corresponding to the terminal device under test, so as to determine the risk category of the sensitive behavior data; Based on the risk category, a security report for the banking application is generated, and a prompt for the security report generation is displayed; In response to the user's viewing operation of the security report generation prompt, the abnormal behavior verification is performed on the terminal device to be detected and the banking application in the trusted execution environment; If the abnormal behavior verification is passed, the security report is de-identified to obtain a de-identified security report. Display the aforementioned desensitization security report.
2. The method according to claim 1, characterized in that, The historical usage data of the banking application includes multiple factors such as user habits, the time of occurrence of the behavior, and the current state of the device, corresponding to the historical usage behavior of the banking application.
3. The method according to claim 2, characterized in that, The step of performing risk analysis processing on the sensitive behavior data based on the historical usage data of the banking applications corresponding to the terminal device under test, in order to determine the risk category of the sensitive behavior data, includes: Cross-comparison processing is performed based on the historical usage data of the bank application and the sensitive behavior data; Based on the cross-comparison results, the risk category of the sensitive behavioral data is determined.
4. The method according to claim 2, characterized in that, The step of performing risk analysis processing on the sensitive behavior data based on the historical usage data of the banking applications corresponding to the terminal device under test, in order to determine the risk category of the sensitive behavior data, includes: Based on the historical usage data of the bank application and the risk tags corresponding to the historical usage data of the bank application, the initial risk category identification model is trained to obtain the trained risk category identification model. Based on the trained risk category recognition model, the sensitive behavior data is processed for risk identification to obtain the risk category of the sensitive behavior data.
5. The method according to any one of claims 1 to 4, characterized in that, The abnormal behavior verification of the terminal device to be detected and the banking application includes at least one of the following: Based on the initial digital fingerprint and the current digital fingerprint of the banking application, verify whether the banking application has been modified; The file information of the terminal device under test is detected to verify whether the terminal device under test has been illegally hacked based on the file information; The system detects forced shutdown operations of the terminal device under test, collects shutdown information based on the forced shutdown operations, and verifies whether the terminal device under test has an abnormal shutdown phenomenon based on the shutdown information.
6. The method according to any one of claims 1 to 4, characterized in that, The step involves collecting sensitive behavioral data of the banking application installed on the terminal device under test in real time within the trusted execution environment corresponding to the security chip of the terminal device under test, based on the startup status of the banking application. This includes: After the bank application is confirmed to be launched, a data transmission channel is established between the bank application and the trusted execution environment corresponding to the security chip of the terminal device under test. The trusted execution environment monitors the application behavior of the banking application installed on the terminal device under test in real time through the data transmission channel. In the trusted execution environment, the application behavior is processed for sensitive behavior identification based on preset sensitive behavior information; If the application behavior is identified as a sensitive behavior, then the sensitive behavior data is collected.
7. The method according to any one of claims 1 to 4, characterized in that, The process of de-identifying the security report to obtain a de-identified security report includes: Identify sensitive information in the sensitive behavior data; The sensitive information is de-identified to obtain the de-identified sensitive information; The sensitive information after desensitization is overlaid on the sensitive behavioral data to obtain the desensitized behavioral data; Based on the desensitized behavioral data and the risk category, a desensitization safety report is generated.
8. The method according to claim 7, characterized in that, The desensitized security report contains hidden anti-counterfeiting dots.
9. The method according to any one of claims 1 to 4, characterized in that, Following the display of the desensitization security report, the following is also included: In response to the user's evidence storage operation, the de-identified security report is stored in segments.
10. The method according to any one of claims 1 to 4, characterized in that, After performing risk analysis on the sensitive behavior data based on the historical usage data of the banking applications corresponding to the terminal device under test to determine the risk category of the sensitive behavior data, the process further includes: If the risk category is high risk, a risk pop-up window will be displayed on the terminal device to be tested; wherein, the risk pop-up window includes a blocking selection area and a temporary non-processing selection area; In response to a user's selection operation in the blocking selection area, risk protection processing is performed; wherein, the risk protection processing includes generating interference information and / or blocking power supply.
11. A security detection device for application behavior, characterized in that, include: The first acquisition module is used to collect sensitive behavior data of the banking application in real time in the trusted execution environment corresponding to the security chip of the terminal device under test, based on the startup status of the banking application installed in the terminal device under test. The risk analysis module is used in the trusted execution environment to perform risk analysis on the sensitive behavior data based on the historical usage data of the bank application corresponding to the terminal device under test, so as to determine the risk category of the sensitive behavior data. The report processing module is used to generate a security report for the banking application based on the risk category and display a security report generation prompt. The verification module is used to verify abnormal behavior of the terminal device to be tested and the banking application in the trusted execution environment in response to the user's viewing operation of the security report generation prompt. The desensitization module is used to desensitize the security report if the abnormal behavior verification is passed, so as to obtain a desensitized security report. The display module is used to display the desensitization security report.
12. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as claimed in any one of claims 1 to 10.
13. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1 to 10.
14. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1 to 10.