首页 | 本学科首页   官方微博 | 高级检索  
     检索      

基于机器学习的Android应用组件暴露漏洞分析
引用本文:邵帅,王眉林,陈冬青,王婷,姜鑫.基于机器学习的Android应用组件暴露漏洞分析[J].北京理工大学学报,2019,39(9):974-977.
作者姓名:邵帅  王眉林  陈冬青  王婷  姜鑫
作者单位:中国信息安全测评中心,北京,100085;北京邮电大学计算机学院,北京,100876
基金项目:国家自然科学基金面上项目(61672534)
摘    要:现阶段已有很多Android应用软件的自动化漏洞检测方法,针对现有漏洞检测方案仍然依赖于先验知识并且误报率较高的问题,本文研究了基于机器学习的Android应用软件组件暴露漏洞的分析方法.在对Android应用软件结构进行全方位分析的基础上,结合组件暴露漏洞模型,建立了相应的机器学习系统,并能够对Android漏洞特征进行提取、数据清理和向量化.结合人工分析与验证,建立了1 000个Android APK样本集,并通过训练实现了组件暴露漏洞的自动化识别,达到了90%以上的精确度. 

关 键 词:机器学习  组件暴露漏洞  Android应用
收稿时间:2018/11/4 0:00:00

Analysis of Android Application Component Exposure Vulnerability Based on Machine Learning
SHAO Shuai,WANG Mei-lin,CHEN Dong-qing,WANG Ting and JIANG Xin.Analysis of Android Application Component Exposure Vulnerability Based on Machine Learning[J].Journal of Beijing Institute of Technology(Natural Science Edition),2019,39(9):974-977.
Authors:SHAO Shuai  WANG Mei-lin  CHEN Dong-qing  WANG Ting and JIANG Xin
Institution:1. China Information Technology Security Evaluation Center, Beijing 100085, China;2. School of Computer, Beijing University of Posts and Telecommunications, Beijing 100876, China
Abstract:There are many automated vulnerability detection methods for Android applications. However, existing vulnerability detection solutions still rely on prior knowledge and lead to high false positive rates. To improve the existing vulnerability detection methods, a machine learning based method was proposed to identify the component exposure vulnerability of Android applications. Analyzing Android application software structure and component exposure vulnerability model, a new machine learning system was established to perform the Android vulnerability features extraction, data cleaning and vectorized operation. Utilizing manual analysis and verification, 1 000 Android APK sample sets were established. Through a large number of training, the system can detect the component exposure vulnerabilities automatically, achieving the accuracy up to 90%.
Keywords:machine learning  component exposure vulnerability  Android application
本文献已被 万方数据 等数据库收录!
点击此处可从《北京理工大学学报》浏览原始摘要信息
点击此处可从《北京理工大学学报》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号