首页 | 本学科首页   官方微博 | 高级检索  
     

一种Android恶意行为检测算法
引用本文:王志强,张玉清,刘奇旭,黄庭培.一种Android恶意行为检测算法[J].西安电子科技大学学报,2015,42(3):8-14.
作者姓名:王志强  张玉清  刘奇旭  黄庭培
作者单位:西安电子科技大学综合业务网理论及关键技术国家重点实验室;中国科学院大学国家计算机网络入侵防范中心
基金项目:国家自然科学基金资助项目(61272481,61303239)
摘    要:提出一种新的Android恶意行为检测算法,该算法使用系统调用序列和控制流序列表征Android应用程序的行为,通过分析已知恶意软件样本库,训练出一个恶意软件特征基和阈值,再计算Android应用程序与特征基的相似度,根据阈值判断目标是否为恶意软件.根据该算法,开发了一个Android恶意软件检测系统SCADect,并在华为U8860真机上对3 000个测试样本进行分类,准确率达到96.8%;针对包含混淆和加密操作的8簇237个恶意样本,该系统的检出率达到89%,明显优于工具Androguard.实验结果表明,SCADect能够抵抗混淆和加密攻击,提高恶意软件检测的准确率和降低误报率.

关 键 词:智能手机  恶意软件  分类  相似度
收稿时间:2014-03-07

Algorithm to detect Android malicious behaviors
WANG Zhiqiang;ZHANG Yuqing;LIU Qixu;HUANG Tingpei.Algorithm to detect Android malicious behaviors[J].Journal of Xidian University,2015,42(3):8-14.
Authors:WANG Zhiqiang;ZHANG Yuqing;LIU Qixu;HUANG Tingpei
Affiliation:(1. State Key Lab. of Integrated Service Networks, Xidian Univ., Xi'an  710071, China; 2. National Computer Network Intrusion Protection Center, University of Chinese Academy of Sciences, Beijing  100190, China)
Abstract:The paper presents a novel Android malware behavioral detection algorithm. The algorithm characterizes Android applications’ behaviors by system call sequences and control flow sequences, trains a malware feature base and a threshold by analyzing known malware samples. Then, we calculate the similarities between the feature base and Android applications, and detect malware by comparing the similarities with the threshold. Finally, an Android malware detection system named SCADect is developed according to the algorithm. The detection accuracy of detecting 3000 samples is up to 96.8%, and the detection rate of classifying 8-cluster obfuscated malware including 237 samples can reach 89%, obviously better than the tool Androguard. The results show that the SCADect is able to resist obfuscated and cryptographic attacks, improves the detection accuracy and reduces the false negative rate.
Keywords:smartphones  malware  classification  similarity  
本文献已被 CNKI 等数据库收录!
点击此处可从《西安电子科技大学学报》浏览原始摘要信息
点击此处可从《西安电子科技大学学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号