首页 | 本学科首页   官方微博 | 高级检索  
     

基于随机森林算法的Android恶意行为识别与分类方法
引用本文:柯懂湘,潘丽敏,罗森林,张寒青.基于随机森林算法的Android恶意行为识别与分类方法[J].浙江大学学报(自然科学版 ),2019,53(10):2013-2023.
作者姓名:柯懂湘  潘丽敏  罗森林  张寒青
作者单位:北京理工大学 信息系统及安全对抗实验中心,北京 100081
摘    要:针对当前Android恶意软件检测方法对检测出的恶意行为无法进行识别和分类的问题,提出基于随机森林(RF)算法的Android恶意行为的识别与分类方法. 该方法在对Android恶意软件的类型进行定义的基础上,利用融合多种触发机制的Android恶意行为诱导方法触发软件的潜在恶意行为;通过Hook关键系统函数对Android软件行为进行采集并生成行为日志,基于行为日志提取软件行为特征集;使用随机森林算法,对行为日志中的恶意行为进行识别与分类. 实验结果表明,该方法对Android恶意软件识别的准确率达到91.6%,对恶意行为分类的平均准确率达到96.8%.

关 键 词:Android安全  机器学习  随机森林(RF)  恶意软件检测  恶意行为分类  

Android malicious behavior recognition and classification method based on random forest algorithm
Dong-xiang KE,Li-min PAN,Sen-lin LUO,Han-qing ZHANG.Android malicious behavior recognition and classification method based on random forest algorithm[J].Journal of Zhejiang University(Engineering Science),2019,53(10):2013-2023.
Authors:Dong-xiang KE  Li-min PAN  Sen-lin LUO  Han-qing ZHANG
Abstract:An Android malware behavior identification and classification method was proposed based on random forest (RF) algorithm aiming at the problem that the existing Android malware detection method cannot identify or classify the detected malicious behavior. The types of Android malware behavior were defined, and the potentially malicious behavior was triggered with a complex Android malicious behavior induction method. Application behavior can be captured by system function hook and transformed into behavior log. Then application behavioral feature set can be extracted from behavior log. The random forest algorithm was used to identify and classify the malicious behavior from the behavior log. The experimental results showed that proposed method had 91.6% accuracy in malware behavior identification and 96.8% accuracy in malicious behavior classification.
Keywords:Android security  machine learning  random forest (RF)  malware detection  malicious behavior classification  
本文献已被 CNKI 等数据库收录!
点击此处可从《浙江大学学报(自然科学版 )》浏览原始摘要信息
点击此处可从《浙江大学学报(自然科学版 )》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号