Android手机定位恶意代码,基于动态特征的Android恶意代码检测和定位方法

Android Malicious Code Detection and Localization based on Runtime Feature

Wang Songhe

1

王淞鹤,1994年,男,硕士,主要研究方向为安卓安全

Guo Yanhui

1

郭燕慧,女,副教授、硕导,主要研究方向为内容安全、机器学习、知识发现

1、School of Cyberspace Security, Beijing University of Posts and Telecommunications, Beijing, 100876

Abstract:Malicious code detection is an important part of Android malware detection, which is used for code research and harmfulness judgment. This part usually requires security analyst to manually analyze and localize malicious code. In order to solve the cumbersome problem of the analysis process, this paper proposes an android malicious code detection and localization method based on runtime feature, which detect malicious behaviors and localizes realted code segments based on the relationship between sensitive API calls and user intentions. This method divides malicious behavior into active trigger and passive trigger based on triggering conditions, and constructing behavior-intention prediction model and multivariate time series based on collected runtime information as detection methods. In this paper, we marked 602 malwares as test set, and the precision rate reached 90.54%. The experimental results show that this method can effectively detect malicious behaviors and localize malicious code.

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值