首页> 外国专利> VERIFICATION THAT PARTICULAR INFORMATION IS TRANSFERRED BY AN APPLICATION

VERIFICATION THAT PARTICULAR INFORMATION IS TRANSFERRED BY AN APPLICATION

机译:验证是否由应用程序传输了特定信息

摘要

The technology includes a method to test what information an application transfers to an external computing device. A user's consent is explicitly obtained before the application transfers certain types of information, such as sensitive information. When a determination is made that an application is transferring sensitive information, a prompt for consent from a user may be provided that is accurate and detailed. In pre-production environments, technology can be used to detect whether this sensitive information is being transferred, and to validate whether a prompt for consent is necessary or unnecessary. To determine this, shimming is used to intercept application calls to APIs that return sensitive information. Requested sensitive information may be substituted with recorded or forged information from those APIs to produce a sentinel or canary. Similarly, network traffic of the application may be analyzed by another shim to determine when the substitute information is present.
机译:该技术包括一种测试应用程序将什么信息传输到外部计算设备的方法。在应用程序传输某些类型的信息(例如敏感信息)之前,已明确获得用户的同意。当确定应用程序正在传输敏感信息时,可以提供准确且详细的用户同意提示。在预生产环境中,可以使用技术来检测是否正在传输此敏感信息,并验证是否需要征求同意的提示。为了确定这一点,可使用匀场来拦截对返回敏感信息的API的应用程序调用。所请求的敏感信息可以替换为那些API记录或伪造的信息,以生成哨兵或金丝雀。类似地,可以由另一个填充程序分析应用程序的网络流量,以确定何时出现替代信息。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号