浏览全部资源
扫码关注微信
[ "夏彬(1994-),男,中国科学院信息工程研究所硕士生,主要研究方向为云安全、大数据安全、移动互联网安全。" ]
[ "邱峰(1983-),男,博士,中国科学院信息工程研究所高级工程师、硕士生导师,主要研究方向为云安全、大数据安全、移动互联网安全。" ]
网络出版日期:2016-10,
纸质出版日期:2016-10-20
移动端阅览
夏彬, 邱峰. 基于Android的木马检测引擎的研究与实现[J]. 电信科学, 2016,32(10):36-41.
Bin XIA, Feng QIU. Research and realization of the Trojan detection engine based on Android[J]. Telecommunications science, 2016, 32(10): 36-41.
夏彬, 邱峰. 基于Android的木马检测引擎的研究与实现[J]. 电信科学, 2016,32(10):36-41. DOI: 10.11959/j.issn.1000-0801.2016257.
Bin XIA, Feng QIU. Research and realization of the Trojan detection engine based on Android[J]. Telecommunications science, 2016, 32(10): 36-41. DOI: 10.11959/j.issn.1000-0801.2016257.
近几年来,Android手机木马病毒发展迅速,Android手机安全问题成为大家关注的焦点,基于Android的木马检测引擎的研究与实现变得日益迫切。为此,提出了一套特征码提取检测算法(FCPA)
FCPA通过调用Android系统库函数获取恶意文件的源路径,利用源路径找到相应文件并对文件进行散列处理,获取文件特征信息,生成一个唯一标识该木马病毒的特征值,然后构建特征码库。同时,设计并实现了木马检测引擎,其利用特征码提取算法快速扫描并检测出手机应用程序中的恶意程序。实验结果表明,该木马检测引擎能够有效检测恶意应用。
During recent years
Trojan viruses on Android systems have greatly evolved
and the frequent security breach of Android systems is rapidly becoming a great concern of contemporary cyber security. The study of Trojan virus detection on Android engine and the application of its outcome has become increasingly significant. A feature code detection algorithm called FCPA got the sourceDir of the known malicious APK files through calling system API. It uses hash algorithm to process these files in order to get the feature information of the files so that the eigenvalue could got which could identify Trojan uniquely. The feature code library was composed of these eigenvalues. The Trojan detection engine called TDE
with the assistance of this feature code library
would be able to take out a quick scan among the files in the cell phone and detect malicious programs in mobile applications. Finally
the designed Trojan detection engine provided a secure environment for the user of the phone.
360 Internet Security Center . China mobile security situation report [EB/OL ] . [ 2016 - 01 - 29 ] . http://zt.360.cn/1101061855.php?did=1101593997&dtid=1101061451.html http://zt.360.cn/1101061855.php?did=1101593997&dtid=1101061451.html .
GORFIELD P . Similarities for fun and profit [J ] . Phrack , 2012 ( 68 ): 2 - 20 .
PEIRAVIAN N , ZHU X . Learning for Android malware detection using permission and API calls [C ] // IEEE 25th International Conference on Tools with Artificial Intelligence , Nov 7 - 9 , 2011 , Boca Raton, Florida, USA . New Jersey : IEEE Press , 2013 : 1082 - 3409 .
TONG Z F . Static industry of Android malware detection [J ] . Jiangsu Communications , 2011 , 28 ( 1 ): 39 - 42 .
BLASTING T , BATYUK L , SCHMIDT A D . An Android application sandbox system for suspicious software detection [C ] // 2010 International Conference on Unwanted Software , Oct 19 - 20 , 2010 , Nancy, France . New Jersey : IEEE Press , 2011 : 55 - 62 .
ZHAO Y HU L , XIONG H . Android malware dynamic analysis scheme based on sandbox information network security [J ] . Information Network Security , 2014 , 30 ( 12 ): 21 - 26 .
JIN Q WUG X , LI D . Antivirus engine and automatic signature extraction algorithm research [J ] . Computer Engineering and Design , 2007 , 3 ( 24 ): 5863 - 5866 .
0
浏览量
537
下载量
0
CSCD
关联资源
相关文章
相关作者
相关机构