首页 | 本学科首页   官方微博 | 高级检索  
     

基于敏感权限及其函数调用图的Android恶意代码检测
引用本文:祝小兰,王俊峰,杜垚,白金荣. 基于敏感权限及其函数调用图的Android恶意代码检测[J]. 四川大学学报(自然科学版), 2016, 53(3): 526-533
作者姓名:祝小兰  王俊峰  杜垚  白金荣
作者单位:四川大学,四川大学计算机学院,成都航空职业技术学院,云南玉溪师范学院
基金项目:国家自然科学基金,国家基础研究重大项目基金,高等学校博士学科点专项科研基金
摘    要:为了有效地检测Android平台上的恶意软件,提出了一种基于敏感权限及其函数调用流程图的静态综合检测方法.通过对恶意软件进行逆向工程分析,构建了包含恶意代码敏感权限与函数调用图的特征库.并采用Munkres匈牙利算法计算待测样本与特征库在相同敏感权限下两个函数调用图之间的编辑距离,得到两个函数调用图之间的相似性,进而得到两个应用程序之间的相似性,据此对恶意软件进行检测识别.实验结果表明,该检测方法具有较高的准确性与有效性,检测效果明显优于工具Androguard.

关 键 词:Android恶意代码检测;逆向工程;敏感权限;函数调用图;图编辑距离;
收稿时间:2015-07-20
修稿时间:2016-01-07

Detecting Android malware based on sensitive permissions and function-call graphs
ZHU Xiao-Lan,WANG Jun-Feng,DU Yao and BAI Jin-Rong. Detecting Android malware based on sensitive permissions and function-call graphs[J]. Journal of Sichuan University (Natural Science Edition), 2016, 53(3): 526-533
Authors:ZHU Xiao-Lan  WANG Jun-Feng  DU Yao  BAI Jin-Rong
Affiliation:Sichuan University,College of Computer Science, Sichuan University,Chengdu Aeronautic Polytechnic,School of Information Technology and Engineering, Yuxi Normal University
Abstract:In order to detect malwares on the Android platform more effectively, we put forward a static comprehensive detection method which combines sensitive permissions with function-call graphs. Firstly, through reverse engineering, we constructed a malware graph database, including sensitive permissions and function-call graphs of numbers of malwares. Then, we used the Munkres algorithm to calculate the graph edit distance between the function-call graphs of the test sample and database at the same sensitive permissions to get the similarity of two function-call graphs, the similarity between two apps and detect malware further. The result shows that our method is highly effective in terms of a high accuracy and a low false positive rate, and it can detect more malwares when compared to the detection rate of Androguard.
Keywords:Android malware detection   reverse engineering   sensitive permissions  function-call graphs   graph edit distance
本文献已被 CNKI 等数据库收录!
点击此处可从《四川大学学报(自然科学版)》浏览原始摘要信息
点击此处可从《四川大学学报(自然科学版)》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号