The present application provides an application
access control method based on
system call restrictions, which relates to the field of
network security technology and provides an application
behavior learning module and an application permission control module; the application
behavior learning module performs the following steps: A1, creating an application behavior
list; A2, dynamic
training monitoring, training and monitoring for each item in the application behavior
list; A3, generating a mapping table, establishing a mapping relationship between each item in the application behavior
list and the
system call; the application permission control module performs the following steps: B1, user
authorization application, initiating an application access request to the
authorization center; B2,
authorization approval, after receiving the application access request, the authorization center authorizes the application according to the requirements; B3, issuing permissions. The present application further refines the
granularity of permission management, reduces the
exposure of applications, protects enterprises, reduces the risk of malicious behavior, protects
system security and data privacy, and improves overall security.