信息网络安全 ›› 2016, Vol. 16 ›› Issue (2): 54-59.doi: 10.3969/j.issn.1671-1122.2016.02.009

• • 上一篇    下一篇

基于Binder信息流的Android恶意行为检测系统

李桂芝1,2(), 韩臻1, 周启惠2, 王雅哲2   

  1. 1.北京交通大学计算机与信息技术学院,北京 100044
    2.中国科学院信息工程研究所信息安全国家重点实验室,北京 100093
  • 收稿日期:2015-10-15 出版日期:2016-02-10 发布日期:2020-05-13
  • 作者简介:

    作者简介: 李桂芝(1990—),女,安徽,硕士研究生,主要研究方向为信息安全;韩臻(1962—),男,浙江,教授,博士,主要研究方向为信息安全体系结构、可信计算;周启惠(1988—),女,山东,硕士,主要研究方向为系统安全;王雅哲(1979—),男,山东,副研究员,博士,主要研究方向为网络空间信任与智能终端安全。

  • 基金资助:
    国家自然科学基金[61202476]

A Detecting System for Android Malicious Behavior Based on Binder Information Flow

Guizhi LI1,2(), Zhen HAN1, Qihui ZHOU2, Yazhe WANG2   

  1. 1. School of Computer and Information Technology, Beijing Jiaotong University, Beijing 100044, China
    2. State Key Laboratory of Information Security, Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100093, China
  • Received:2015-10-15 Online:2016-02-10 Published:2020-05-13

摘要:

目前基于Android系统的恶意软件泛滥,其恶意行为不仅给用户的财产安全带来巨大的威胁,也制约移动终端应用的发展。文章针对这种现象设计并实现了一种基于Binder信息流的Android恶意行为检测系统。根据收集到的应用间通信信息,以检测隐私数据泄露为具体安全需求,构建信息流矢量图展示应用通信路径,基于通信内容利用图的遍历进行恶意行为分析。文章对300个应用进行分析,发现有30.7%的应用存在非法访问隐私数据的恶意行为。性能测试结果表明,文章所提方案对Android系统仅带来6.9%的性能损耗。

关键词: Android, Binder信息流, 隐私数据, 恶意行为

Abstract:

Currently, malwares based on the Android system are in flood. The malicious behavior not only brings a huge threat to users’ property, but also limits the development of mobile terminal application. In order to solve this problem, this paper designs and realizes a system for malicious behavior detection based on Binder information flow. According to the collected universal information, this paper sets privacy data detection as the specific safety requirements to discover the malicious behavior of applications, and builds information-flow graph showing the communication path between applications. Malicious behavior analysis is based on communication content and graph traversal. This paper analyzes 300 applications and finds 30.7% of the applications have malicious behavior of illicit access to private data. The performance test shows that the proposed scheme in this paper only brings 6.9% performance loss to Android system.

Key words: Android, Binder information flow, privacy data, malicious behavior

中图分类号: