郑鹭斌. Android恶意软件的静态分析方法及评判模型研究[J]. 微电子学与计算机, 2015, 32(9): 157-160. DOI: 10.19304/j.cnki.issn1000-7180.2015.09.032
引用本文: 郑鹭斌. Android恶意软件的静态分析方法及评判模型研究[J]. 微电子学与计算机, 2015, 32(9): 157-160. DOI: 10.19304/j.cnki.issn1000-7180.2015.09.032
ZHENG LU-bin. Research on Static Analysis Methods and Evaluation Models of Android Malware[J]. Microelectronics & Computer, 2015, 32(9): 157-160. DOI: 10.19304/j.cnki.issn1000-7180.2015.09.032
Citation: ZHENG LU-bin. Research on Static Analysis Methods and Evaluation Models of Android Malware[J]. Microelectronics & Computer, 2015, 32(9): 157-160. DOI: 10.19304/j.cnki.issn1000-7180.2015.09.032

Android恶意软件的静态分析方法及评判模型研究

Research on Static Analysis Methods and Evaluation Models of Android Malware

  • 摘要: 针对Android软件的特殊格式,利用反编译的控件库,实现APK安装包的内容解析,并读取软件的配置文件、smail文件、代码文件等内容.归纳现有的恶意软件静态分析方法,提出一种更全面的静态分析方法,分析内容包括申请权限、头文件、服务、系统API、常量等关键代码特征信息,并建立恶意代码特征库,然后,利用正则表达式进行特征模糊匹配,检测软件的可疑恶意代码.最后,提出一个恶意系数的量化判定模型.

     

    Abstract: According to the special format of android software,this paper use the decompilation control library to realize analysis of apk installation package,then read the software configuration files,smail files,code documents and so on.After summarizing the existing static analysis methods of malicious software,it present a comprehensive static analysis method,includes permission, header files,services,system API,constant and other key code feature.This paper establish a database of malicious code feature,and use the regular expression to fuzzy match suspicious malicious code. Finally, it proposed a malicious coefficient quantization and determination model.

     

/

返回文章
返回