摘要
为了解决对Android共谋攻击检测效率差和准确率低的问题,提出基于组件通信的Android共谋攻击检测模型。首先,提取已知应用的特征生成特征向量集。其次,对权限特征向量集进行训练和分类,生成安全策略规则集。然后,根据组件和通信方式特征向量集生成组件通信有限状态机并优化安全策略规则集。最后,通过提取待测应用的特征向量集生成新状态机,与已优化安全策略规则集进行匹配检测共谋攻击。实验结果表明,所提检测模型具有较好的检测效率和较高的准确率。
In order to solve the problem of poor efficiency and low accuracy of Android collusion detection, an Android collusion attack model based on component communication was proposed. Firstly, the feature vector set was extracted from the known applications and the feature vector set was generated. Secondly, the security policy rule set was generated through training and classifying the privilege feature set. Then, the component communication finite state machine according to the component and communication mode feature vector set was generated, and security policy rule set was optimized. Finally, a new state machine was generated by extracting the unknown application's feature vector set, and the optimized security policy rule set was matched to detect privilege collusion attacks. The experimental results show that the proposed model has better detective efficiency and higher accuracy.
作者
杨宏宇
王在明
YANG Hongyu;WANG Zaiming(School of Computer Science and Technology,Civil Aviation University of China,Tianjin 300300,China)
出处
《通信学报》
EI
CSCD
北大核心
2018年第6期27-36,共10页
Journal on Communications
基金
国家科技重大专项基金资助项目(No.2012ZX03002002)
中国民航科技基金资助项目(No.MHRD201009
No.MHRD201205)~~