节点文献

基于抽象API调用序列的Android恶意软件检测方法

ANDROID MALWARE DETECTION METHOD BASED ON ABSTRACT API CALL SEQUENCES

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 崔艳鹏颜波胡建伟

【Author】 Cui Yanpeng;Yan Bo;Hu Jianwei;School of Cyber Engineering, Xidian University;

【机构】 西安电子科技大学网络与信息安全学院

【摘要】 随着Android版本的不断更替,以及恶意软件的代码混淆技术的发展,主流的静态检测方法开始面临检测效率逐年下降的问题。针对上述问题,提出一种基于抽象API调用序列的Android恶意软件检测方法。该方法采用API包名、混淆名和自定义名来抽象API调用序列,使得抽象出来的序列不依赖API版本,同时又包含混淆代码特征,具有更好的容错性。在此基础上,计算抽象API调用序列之间的转移概率矩阵作为分类特征,采用RandomForest分类算法进行恶意软件检测。实验结果表明,该方法对API版本依赖性小,且判别准确率高于一般使用API调用序列作为特征的判别方法,从而能更有效地检测未知应用软件的恶意性。

【Abstract】 With the continuous update and replacement of the Android version, as well as the development of code obfuscation techniques of malware, mainstream static detection methods are beginning to face the problem of decreasing detection efficiency year by year. Aiming at the above problems, we proposed a Android malware detection method based on abstract API call sequences. The method used API package name, obfuscated name and self-defined name to abstract the API call sequence, so that the abstracted sequence did not depend on the API version. And it contained obfuscated code features, which had better fault tolerance. On this basis, the transition probability matrix between abstract API call sequences was calculated as the classification feature, and the RandomForest classification algorithm was used for malware detection. The experimental results show that the method has little dependence on the API version, and the discriminant accuracy is higher than the commonly used API call sequence as the feature discriminant method, so that the maliciousness of the unknown application software can be detected more effectively.

  • 【文献出处】 计算机应用与软件 ,Computer Applications and Software , 编辑部邮箱 ,2019年09期
  • 【分类号】F49;TP309
  • 【被引频次】10
  • 【下载频次】322
节点文献中: 

本文链接的文献网络图示:

本文的引文网络