The application relates to the technical field of APP detection
data processing, and discloses a harmful APP effective
core domain name deep detection method, which comprises the following steps: firstly, a sandbox environment is constructed, a network
proxy service is constructed in the sandbox environment, and communication traffic information of an APP is comprehensively acquired; then, the APP accesses
the Internet through a TUN mode connection gateway in the sandbox test environment; internal operations of the APP are automatically operated, including login, registration and refreshing operations; running analysis is carried out by limiting network bandwidth,
delay and
packet loss rate parameters;
core domain name analysis is carried out, specifically including deep detection of traffic logs; a training model is established according to the traffic logs, the traffic logs are analyzed through the model, a
machine learning
decision tree algorithm or a
data analysis method is used for model analysis, and effective situation data of the APP is confirmed and analyzed. The application constructs an APP communication log analysis model based on a
decision tree algorithm, and identifies suspected
core domain names based on dimensions such as communication behavior and communication content.