信息网络安全 ›› 2019, Vol. 19 ›› Issue (11): 56-62.doi: 10.3969/j.issn.1671-1122.2019.11.008

• 技术研究 • 上一篇    下一篇

基于签名查验的移动终端应用软件合法性判别技术

李涛, 时俊贤(), 胡爱群   

  1. 东南大学网络空间安全学院,江苏南京 210096
  • 收稿日期:2019-03-26 出版日期:2019-11-10 发布日期:2020-05-11
  • 作者简介:

    作者简介:李涛(1984—),男,江苏,副教授,博士,主要研究方向为智能安全、可信计算、移动终端安全;时俊贤(1996—),男,江苏,硕士研究生,主要研究方向为网络空间安全;胡爱群(1964—),男,江苏,教授,博士,主要研究方向为无线网络安全、物理层安全技术。

  • 基金资助:
    国家自然科学基金[61601113]

Signature Verification Based Legality Discrimination Technology for Mobile Terminal APPs

Tao LI, Junxian SHI(), Aiqun HU   

  1. School of Cyber Science and Engineering, Southeast University, Nanjing Jiangsu 210096, China
  • Received:2019-03-26 Online:2019-11-10 Published:2020-05-11

摘要:

随着移动终端设备的不断普及,越来越多的用户选择安装第三方应用软件以满足自己不同的需求。由于缺乏对应用软件合法性的辨别能力,大多数用户在不经意间安装了非法应用软件。非法应用软件通过修改合法应用软件的源码并在其中植入恶意代码后重新打包生成。修改他人应用软件的行为侵犯了原软件开发者的合法权益,同时其中包含的恶意代码会获取用户的信息,导致用户的隐私受到侵犯、财产受到损失。非法应用软件已经严重威胁到移动终端设备的安全。文章提出一种基于签名查验的判别技术,通过采集合法应用软件数字证书中的特征参数建立白名单库,将待测应用软件数字证书中对应的特征参数与白名单库中的数据进行比对,从而判定其合法性。实验结果表明,该技术检测速度快、准确率高,具有很强的实用性。

关键词: 移动终端应用软件, 合法性判别, 数字证书, 白名单

Abstract:

With the increasing popularity of mobile terminal devices, more and more users choose to install third-party application software to meet their different needs. Due to the lack of ability to discriminate against the legality of applications, most users have inadvertently installed illegal applications. Illegal application software is repackaged by modifying the source code of the legitimate application software and embedding malicious code in it. The modification of other people’s application software infringes the legitimate rights and interests of the original software developer, and the malicious code contained therein will obtain the user’s information, resulting in the user’s privacy violation and property loss. The illegal application software has seriously threatened the security of the mobile terminal device. This paper proposes a discriminant technology based on signature verification. The whitelist database is built by collecting the characteristic parameters in the digital certificate of the legal application software, and then the corresponding feature parameters in the digital certificate of the application software to be tested are compared with the data in the whitelist database to determine its legality. The experimental results show that the technology has high detection speed, high accuracy and strong practicability.

Key words: mobile terminal application software, legality discrimination, digital certificate, whitelist

中图分类号: