期刊文献+

基于沙盒的Android恶意软件检测技术研究 被引量:7

Malware detection technology research of Android platform based on sandbox
下载PDF
导出
摘要 随着互联网技术和计算机技术的高速发展,人们获取资源和服务变得更加方便快捷了,但与之伴随而来的安全问题也日益突出。特别是在使用广泛的移动终端上,窃取信息、恶意吸费等恶意软件层出不穷。由于受到资源和计算能力的限制,移动终端无法安装功能强大、性能要求高的病毒查杀软件。本文从实际出发,针对移动终端对安全的需求和现有查杀软件存在的弊端进行了深入的分析,提出了一种基于沙盒的结合移动端和云端的恶意软件检测技术。该技术采用了基于动态分析的沙盒技术,从一定程度上弥补了传统的静态分析方法所存在的不足,沙盒所特有的隔离环境,同时保证在系统执行检测任务时免遭恶意程序的破坏。另外,考虑到移动终端的局限性和检测过程的可靠性,在移动终端经过预处理后,使用高效的比对算法进行二进制比对,同时通过网络将APK中的class字节码文件上传到云端,通过在云端的虚拟机中运行执行代码进行进一步检测,从而提高检测的可靠性和效率。 With the rapid development of Internet technology and computer technology, people's access to resources and services become more convenient, but the security issue with the attendant increasingly prominent. Especially in the use of a wide range of mobile devices, steal information, malicious suction fee malware endless. Due to limited resources and computing power, the mobile terminal cannot install a powerful, high performance requirements virus killing software. This article from the reality, for mobile terminal security requirements and existing software Disadvantages killing depth analysis,the malware detection technology based on a combination of sandbox mobile terminal and the cloud. The technology uses sandbox technology based dynamic analysis, to some extent, compensate for the shortcomings of traditional static analysis methods exist, sandbox unique isolated environment, while ensuring that malicious programs from the system to perform inspection tasks in damage. In addition, taking into account the limitations and reliability of the detection process of the mobile terminal, the mobile terminal after pretreatment, the use of efficient than binary comparison algorithm, and through a network of APK class bytecode files uploaded to the cloud by the virtual machine to execute code to run in the cloud for further testing to improve the reliability and efficiency of detection.
作者 林鑫
机构地区 南京理工大学
出处 《电子设计工程》 2016年第12期48-50,53,共4页 Electronic Design Engineering
关键词 沙盒 ANDROID 恶意软件 云计算 sandbox android malware detection cloud computing
  • 相关文献

参考文献7

二级参考文献94

  • 1黄涛,陈宁江,魏峻,张文博,张勇.OnceAS/Q:一个面向QoS的Web应用服务器[J].软件学报,2004,15(12):1787-1799. 被引量:28
  • 2方崇智 萧德云.过程辨识[M].北京:清华大学出版社,2003..
  • 3周明,孙树栋.遗传算法原理及应用[M].北京:国防工业出版社,2001.
  • 4BIRMAN K P, GLADE B B. Consistent Failure Reporting in Reliable Communication Systems [R].Ithace:Cornell University, 1993.
  • 5BOUTEILLER A, DESPREZ F. Fault Tolerance Management for a Hierarchical Grid RPC Middleware[C]. Proceedings of the 8th IEEE International Symposium on Cluster Computing and Grid (CCGRID 2008), IEEE Press, 2008.
  • 6TAY B H, ANANDA A L. A Survey of Remote Procedure Calls[J]. ACM SIGOPS Operating Systems Review, 1990,24 (3):68-79.
  • 7LAZOWSKA E D, ZAHORJAN J, Graham G S, et al. Quantitative System Performance: Computer System Analysis Using Queueing Network Models [M]. Upper Saddle River: Prentice-Hall, Inc., 1984.
  • 8WANG G J, WANG C Z, CHEN A, et al. Service Level Management Using QoS Monitoring, Diagnostics, and Adaptation for Networked Enterprise Systems [C]. Washington DC: Proceedings of the 9th IEEE International EDOC Enterprise Computing Conference, IEEE Computer Society, 2005 : 239-250.
  • 9Steven M P.Contrary to what you've heard,Android is almost impenetrable to malware[EB/OL].[2014-06-23].http://qz.com/131436/contrary-to-what-youveheard-android-is-almost-impenetrable-to-malware/.
  • 10Zhou Y,Jiang X.An analysis of the AnserverBot trojan[EB/OL].[2014-06-23].http://www.csc.ncsu.edu/faculty/jiang/pubs/AnserverBot_Analysis.pdf.

共引文献85

同被引文献37

引证文献7

二级引证文献21

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部