通信学报 ›› 2014, Vol. 35 ›› Issue (8): 78-85.doi: 10.3969/j.issn.1000-436x.2014.08.011

• 学术论文 • 上一篇    下一篇

Android恶意软件检测技术分析和应用研究

文伟平,梅瑞,宁戈,汪亮亮   

  1. 北京大学 软件与微电子学院,北京 102600
  • 出版日期:2014-08-25 发布日期:2017-06-29
  • 基金资助:
    国家自然科学基金资助项目

Malware detection technology analysis and applied research of android platform

Wei-ping WEN,Rui MEI,Ge NING,Liang-liang WANG   

  1. Department of Information Security, School of Software and Microelectronics, Peking University, Beijing 102600, China
  • Online:2014-08-25 Published:2017-06-29
  • Supported by:
    The National Natural Science Foundation of China

摘要:

针对Android平台安全问题,提出了手机端和服务端协作的恶意代码检测方案,手机端应用主要采用基于permission检测技术,实现轻量级的检测。服务端检测系统主要负责对手机端提交的可疑样本进行检测,同时实现了软件行为分析,特征库更新,与手机端同步等功能。其中服务端检测技术包括基于permission检测技术、基于字节码静态检测技术和基于root权限的动态检测技术。实验测试结果表明,3种检测技术能达到较好的检测效果。

关键词: 恶意代码检测, 静态分析, 动态分析, 权限分析

Abstract:

For the Android platform security problem, a mobile client and server collaborative malware detection pro-posal was proposed, where mobile client application was mainly based on permission detection technology and imple-mented lightweight testing. The server-side detection system is mainly responsible for testing suspicious samples submit-ted by the mobile terminals, meanwhile implements the functions of software behavior analysis, signature library updates, and mobile client synchronization, etc. The server-side detection techniques include permission-based detection technol-ogy, bytecode-based static detection technology and root-based dynamic detection technology. The result of the experi-ment shows that the three detection techniques can achieve better detection results.

Key words: malcode detection, static analysis, dynamic analysis, permission analysis

No Suggested Reading articles found!