Research on android malware detection and interception based on behavior monitoring |
| |
Authors: | Guojun Peng Yuru Shao Taige Wang Xian Zhan Huanguo Zhang |
| |
Affiliation: | 1. Key Laboratory of Aerospace Information Security and Trust Computing, Ministry of Education, Wuhan, 430072, Hubei, China 2. School of Computer, Wuhan University, Wuhan, 430072, Hubei, China
|
| |
Abstract: | Focusing on the sensitive behaviors of malware, such as privacy stealing and money costing, this paper proposes a new method to monitor software behaviors and detect malicious applications on Android platform. According to the theory and implementation of Android Binder interprocess communication mechanism, a prototype system that integrates behavior monitoring and intercepting, malware detection, and identification is built in this work. There are 50 different kinds of samples used in the experiment of malware detection, including 40 normal samples and 10 malicious samples. The theoretical analysis and experimental result demonstrate that this system is effective in malware detection and interception, with a true positive rate equal to 100% and a false positive rate less than 3%. |
| |
Keywords: | |
本文献已被 CNKI SpringerLink 等数据库收录! |
|