首页 | 本学科首页   官方微博 | 高级检索  
     

基于混合特征的Android恶意软件静态检测
引用本文:卢文清,;何加铭,;曾兴斌,;樊玲慧. 基于混合特征的Android恶意软件静态检测[J]. 无线电通信技术, 2014, 0(6): 64-68
作者姓名:卢文清,  何加铭,  曾兴斌,  樊玲慧
作者单位:[1]宁波大学通信技术研究所,浙江宁波315211; [2]浙江省移动网应用技术重点实验室,浙江宁波315211; [3]宁波新然电子信息科技发展有限公司,浙江宁波315211
基金项目:浙江省移动网络应用技术联合重点实验室(2010E10005); 浙江省新一代移动互联网用户端软件科技创新团队(2010R50009); 基于TD-LTE的无线宽带政务示范网的评估测试与优化研究2011C11042; 新一代移动互联网移动采编平台研究(2012R10009-20)
摘    要:当前智能手机市场中,Android占有很大的市场份额,又因其他的开源,基于Android系统的智能手机很容易成为攻击者的首选目标。随着对Android恶意软件的快速增长,Android手机用户迫切需要保护自己手机安全的解决方案。为此,对多款Android恶意软件进行静态分析,得出Android恶意软件中存在危险API列表、危险系统调用列表和权限列表,并将这些列表合并,组成Android应用的混合特征集。应用混合特征集,结合主成分分析(PCA)和支持向量机(SVM),建立Android恶意软件的静态检测模型。利用此模型实现仿真实验,实验结果表明,该方法能够快速检测Android应用中恶意软件,且不用运行软件,检测准确率较高。

关 键 词:混合特征  主成分分析法  支持向量机  Android应用  恶意检测

Android Malware Static Detection Based on Hybrid Features
Affiliation:LU Wen-qing , HE Jia-ming, ZENG Xing-bin, FAN Ling-hui ( 1.Institute of Communication, Ningbo University, Ningbo Zhejiang 315211, China ; 2.Key Laboratory of Mobile Internet Application Technology of Zhejiang Province, Ningbo Zhejiang 315211, China; 3.Ningbo SUNRU ELEC.INFO.ST&D CO., LTD, Ningbo Zhejiang 315211, China)
Abstract:Android occupies a large share in the current smart phone market,and due to its open source, smart phones based on Android are very easy to become the first targets of attacks.With the rapid growth of Android mobile malware,Android owners urgently need security solutions to protect their mobile phones.In this paper,static analysis is performed on many types of Android malware, and a conclusion is got that there are dangerous API list,dangerous system call list and permission list in Android malware.These lists are combined into a hybrid feature set which is then used in combination with principal component analysis (PCA) and support vector machine (SVM) to establish an Android malware static testing model.The simulation experiments realized through this model show that the method can rapidly detect malicious software and it' s not necessary to run software,the detection accuracy is also higher.
Keywords:hybrid feature  principal component analysis  support vector machine  Android applications  malware detection
本文献已被 维普 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号