信息网络安全 ›› 2016, Vol. 16 ›› Issue (8): 18-23.doi: 10.3969/j.issn.1671-1122.2016.08.004

• • 上一篇    下一篇

一种基于Android内核的APP敏感行为检测方法及实现

文伟平(), 汤炀, 谌力   

  1. 北京大学软件与微电子学院,北京 102600
  • 收稿日期:2016-04-18 出版日期:2016-08-20 发布日期:2020-05-13
  • 作者简介:

    作者简介: 文伟平(1976—),男,湖南,副教授,博士,主要研究方向为网络攻击与防范、恶意代码研究、信息系统逆向工程等;汤炀(1992—),男,广西,硕士研究生,主要研究方向为Android安全;谌力(1991—),男,湖北,硕士研究生,主要研究方向为Android 安全。

  • 基金资助:
    国家自然科学基金[61170282]

An APP Sensitive Behaviors Detection Method Based on Android Kernel and Its Implementation

Weiping WEN(), Yang TANG, Li SHEN   

  1. School of Software & Microelectronics, Peking University, Beijing 102600, China
  • Received:2016-04-18 Online:2016-08-20 Published:2020-05-13

摘要:

进入移动智能终端时代后,Android手机操作系统由于其开放、免费的特点,成为市场上的主流操作系统之一。然而,大量针对Android系统编写的病毒、木马和恶意软件已经严重威胁到智能手机用户的个人隐私和财产安全。虽然在Android系统中进行敏感操作必须向系统申请相应的权限,Android系统中也存在权限控制相关的系统模块,但是恶意软件可以借助系统漏洞或第三方程序漏洞进行攻击。鉴于Android应用敏感行为检测的需要,文章研究分析了现有Android系统中应用程序行为检测方法,设计并实现了针对Android系统应用程序的动态行为监测系统,该系统能够实时监控应用程序的敏感行为,为恶意程序检测提供帮助。

关键词: Android应用, 敏感行为, 动态监测

Abstract:

In the era of intelligent mobile terminal, because of the characteristics of openness and free of charge, Android has become one of the major operation systems on the market. However, a large number of Android viruses, Trojans and malicious software have been serious threats to the privacy and property securities of smart phone users. In the Android operation system, although it is necessary to apply the authorities to the system for sensitive operations, and there are some system modules related to authority control, malicious software can use the system vulnerabilities or third party program vulnerabilities to carry out the attack. To meet the need of Android applications sensitive behaviors detection, this paper analyzes the popular applications behaviors detection tools in the Android system, designs and implements an Android applications dynamic detection system. The system can monitor the Android applications sensitive behaviors in real time, and provides help for the detection of malicious programs.

Key words: Android application, sensitive behavior, dynamic monitor

中图分类号: