许家乐, 乔喆, 王晓晴, et al. Research and application of privacy information detection and protection technology for mobile internet users[J]. 2019, 32(12): 12-17+22.
许家乐, 乔喆, 王晓晴, et al. Research and application of privacy information detection and protection technology for mobile internet users[J]. 2019, 32(12): 12-17+22. DOI: 10.13992/j.cnki.tetas.2019.12.003.
Research and application of privacy information detection and protection technology for mobile internet users
摘要
智能终端及应用作为"大连接"中的重要节点和业务载体
直接或间接接触大量用户敏感隐私信息。近年来
APP强制授权、过度索权和超范围收集个人信息的现象大量存在
违法违规使用个人信息的问题十分突出
用户隐私泄露的情况愈演愈烈
安全及隐私问题引发社会广泛关注。本文根据不同源头的APP隐私安全风险全面梳理排查
创新提出"静态权限检测+动态行为特征+网络DPI智能分析"的隐私信息检测防护技术体系
实现了敏感权限智能分析、违规索权动态监控、隐私泄露探测预警和敏感信息深度追踪
确保移动应用APP安全、可信、可控
保障了业务单位和用户隐私安全权益。
Abstract
As an important node and business carrier in "big connection"
intelligent terminals and applications have direct or indirect contact with a large number of users’ sensitive privacy information. In recent years
APP forced authorization
excessive claim of rights
and over-range collection of personal information abound. The problem of illegal use of personal information is very prominent. The leakage of users’ privacy is getting worse and worse. Security and privacy issues have aroused widespread concern in society. This paper comprehensively sorts out and inspects APP privacy security risks from different sources
and innovatively proposes a privacy information detection and protection technology system of "static permission detection+dynamic behavior characteristics+network DPI intelligent analysis"
which realizes sensitive permission intelligent analysis
illegal claim dynamic monitoring
privacy leak detection and early warning
sensitive information depth tracking
ensures mobile application APP to be safe
credible and controllable
and protects the privacy security rights and interests of business units and users.