节点文献

Android运行时恶意行为检测模型研究

A Detection Model of Malware Behaviors on Android

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 董航李祺董枫彭勇徐国爱

【Author】 DONG Hang;LI Qi;DONG Feng;PENG Yong;XU Guo-ai;Beijing University of Posts and Telecommunications;China Information Technology Security Evaluation Center;

【机构】 北京邮电大学计算机学院信息安全中心中国信息安全测评中心

【摘要】 为实现Android应用程序恶意行为的有效分析,提出了基于HMMs-SVM的程序行为分类模型,将隐马尔可夫模型(HMM)和支持向量机(SVM)相结合,以动态行为序列作为关键特征,对移动应用软件运行中的网络收发、文件访问等行为建模.该模型融合了HMM和SVM的优势,并克服了二者的不足,适合于在获取连续动态行为特征序列后进行行为分类.实验结果表明,该方法分析召回率较高,可以有效对应用中的异常行为进行捕捉,并可以将其按类型分类.

【Abstract】 A detection method was proposed to analyze the malicious behavior on Android,that combines hidden-Markov model( HMM) with support vector machine( SVM) for modeling as well as construct model for behaviors like networking and data accessing. This model takes advantage of both HMM and SVM and overcomes the shortcomings inside,and it is suitable for classification using dynamic behavior sequences. Experiments show that this method can capture the abnormal behaviors with high accuracy rate and lower false positive rate.

【基金】 国家自然科学基金项目(61302087);国家科技支撑计划项目(2012BAH06B02);教育部博士点基金项目(20120005110017)
  • 【文献出处】 北京邮电大学学报 ,Journal of Beijing University of Posts and Telecommunications , 编辑部邮箱 ,2014年03期
  • 【分类号】TP309;TP311.52
  • 【被引频次】9
  • 【下载频次】257
节点文献中: 

本文链接的文献网络图示:

本文的引文网络