The embodiment of the invention provides a method and
system for privacy disclosure detection. The method comprises the steps of searching a sensitive
data source, a disclosure point and an application program interface of a
callback function in an installation
package according to a constructed sensitive
data source, an application program interface table of disclosure points and an application program interface table of
callback functions, and obtaining the sensitive
data source, the disclosure point and the
callback function in the installation
package, and establishing an
assembly life cycle model through the sensitive data source, the disclosure point and the callback function in the installation
package; generating a virtual main function through the callback function in the installation package and the
assembly life cycle model; causing the virtual main function to generate an inter-function
control flow diagram through conversion, taking the sensitive data source in the installation package as an analysis starting point, analyzing the inter-function
control flow diagram according to a data flow taint analysis
algorithm, and obtaining a suspicious path of privacy disclosure; and outputting the suspicious path of privacy disclosure. Privacy disclosure behaviors in an application program
assembly can be effectively found.