首页 | 本学科首页   官方微博 | 高级检索  
     

Android恶意程序行为分析系统设计
引用本文:李静华 慕德俊 杨鸣坤 胡 伟. Android恶意程序行为分析系统设计[J]. 北京邮电大学学报, 2014, 37(Z1): 104-107. DOI: 10.13190/j.jbupt.2014.s1.020
作者姓名:李静华 慕德俊 杨鸣坤 胡 伟
作者单位:西北工业大学 自动化学院, 西安 710072
基金项目:国家自然科学基金项目(61303224);高校博士点基金项目(20126102110036);西北工业大学研究生创业种子基金项目(Z2014018)
摘    要:提出了一种基于行为的Android恶意程序分析系统(nDroidAS)设计. nDroidAS加入客户端组件监控用户设备上的Android安装包(APK)安装操作,以及时分析待安装应用程序. 服务器端在虚拟环境中安装、运行应用程序,执行动态行为分析检出恶意程序;同时,抓取互联网中的APK程序包并提前分析,建立结果缓存,加快对用户分析请求的响应. 构建了简化的nDroidAS原型系统,分析了部分APK程序样本. 验证结果表明:nDroidAS能有效监控Android设备中的APK安装操作并及时响应客户端分析请求,是一种可行的恶意程序行为分析系统方案.

关 键 词:Android  恶意程序  行为分析  
收稿时间:2013-11-08

Design on Android Malware Behavior Analysis System
LI Jing-hua,MU De-jun,YANG Ming-kun,HU Wei. Design on Android Malware Behavior Analysis System[J]. Journal of Beijing University of Posts and Telecommunications, 2014, 37(Z1): 104-107. DOI: 10.13190/j.jbupt.2014.s1.020
Authors:LI Jing-hua  MU De-jun  YANG Ming-kun  HU Wei
Affiliation:School of Automation, Northwestern Polytechnical University, Xi'an 710072, China
Abstract:Consisting of nDroidC (client) and nDroidS(server), a behavior-based Android malware analysis system: nDroidAS is proposed. Application installation events on the Android device are monitored by nDroidC, which generates analysis requests while an application is to be installed. The target application is installed in nDroidS, by which dynamic feature vectors of the application are collected and analyzed to detect the malicious ones. Meanwhile, to pre-analyze applications, an Android package(APK) fetcher is designed in nDroidS to fetch APK samples from app markets. Some key technologies of the system such as feature vectors selection and interaction simulation are also discussed. A simplified prototype of nDroidAS is built, which is able to analyze Android malwares dynamically and fetch APK samples in the wild. Experiments show that the proposed system architecture is feasible.
Keywords:Android  malware  behavior analysis  
本文献已被 CNKI 等数据库收录!
点击此处可从《北京邮电大学学报》浏览原始摘要信息
点击此处可从《北京邮电大学学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号