基于关联规则的Android恶意软件检测技术  

The Android Malware Detection Technology Based on Association Rules

在线阅读下载全文

作  者:方加娟[1] 丁乙恒 FANG Jia-juan;DING Yi-heng(School of Information Engineering and Big Data,Zhengzhou Technical College,Zhengzhou 450121,China;College of Computer and Communication Engineering,Zhengzhou University of Light Industry,Zhengzhou 450000,China)

机构地区:[1]郑州职业技术学院信息工程与大数据学院,河南郑州450121 [2]郑州轻工业大学计算机与通信工程学院,河南郑州450000

出  处:《电脑与信息技术》2024年第3期115-118,共4页Computer and Information Technology

摘  要:由于Android系统的开放性和多样性,使得该系统的受攻击面非常广泛,同时随着入侵技术和手段不断升级,导致恶意软件难以被检测到。为此,提出基于关联规则的Android恶意软件检测技术。利用计算机编程语言中dpke库对wireshark配置脚本文件解析,提取恶意软件流量,并获取恶意软件静态特征,通过对恶意软件流量聚类分析,利用频繁项集与关联规则计算最小支持度与最小置信度,提取到关联规则,将关联规则与规则库比对,识别检测恶意软件类型,以此实现基于关联规则的Android恶意软件检测。实验证明,设计技术查准率在95%以上,F_measure值在0.95以上,在Android安全防护方面具有良好的应用前景。Due to the openness and diversity of the Android system,the attack surface of the system is very extensive,and with the continuous upgrading of intrusion techniques and methods,it is difficult to detect malicious software.Therefore,an Android malware detection technology based on association rules is proposed.The dpke library in the computer programming language was used to parse the wireshark configuration script file,extract the malware traffic,and obtain the static characteristics of the malware.Through the cluster analysis of the malware traffic,the minimum support and minimum confidence were calculated by using frequent item sets and association rules,and the association rules were extracted and compared with the rule library.Identify and detect the types of malware,so as to realize the detection of Android malware based on association rules.The experimental results show that the accuracy of the design technology is above 95%and the F_measure value is above 0.95,which has a good application prospect in Android security protection.

关 键 词:关联规则 ANDROID 恶意软件 计算机编程语言 F_measure值 

分 类 号:TP309[自动化与计算机技术—计算机系统结构]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象