| 注册
首页|期刊导航|计算机技术与发展|通过AndroidManifest和API调用追踪的恶意检测

通过AndroidManifest和API调用追踪的恶意检测

郑尧 王轶骏 薛质

计算机技术与发展2017,Vol.27Issue(3):126-130,5.
计算机技术与发展2017,Vol.27Issue(3):126-130,5.DOI:10.3969/j.issn.1673-629X.2017.03.026

通过AndroidManifest和API调用追踪的恶意检测

Android Malware Detection of Calls Tracing with AndroidManifest and API

郑尧 1王轶骏 1薛质1

作者信息

  • 1. 上海交通大学 电子信息与电气工程学院,上海 200240
  • 折叠

摘要

Abstract

A static feature-based mechanism is studied to provide a static analysis method for detection of the Android malware. In order to identify the intention of different Android malware,all kinds of clustering algorithms are applied to enhance the malware modeling ca-pability to any Android procedure. Besides,a system,called XDroidMat,is developed. The XDroidMat extracts the information from each application' s manifest file and regards components as entry points drilling down for tracing API Calls related to permissions. Then it uses k-means algorithm to strengthen the malware modeling capability. The number of clusters is decided by Singular Value Decomposition ( SVD) method on the low rank approximation. Finally,it uses kNN algorithm to classify the application as benign or malicious. The ex-perimental results show XDroidMat can get 98. 12% accuracy and do well in detecting the Android malware.

关键词

Android恶意应用/静态分析/基于特征/组件间通信

Key words

Android malware/static analysis/feature-based/ICC

分类

信息技术与安全科学

引用本文复制引用

郑尧,王轶骏,薛质..通过AndroidManifest和API调用追踪的恶意检测[J].计算机技术与发展,2017,27(3):126-130,5.

基金项目

国家自然科学基金资助项目(61332010) (61332010)

计算机技术与发展

OACSTPCD

1673-629X

访问量0
|
下载量0
段落导航相关论文