Android malicious application detection system based on multi-operation environment behavior comparison
A malicious application and operating environment technology, applied in the field of network security, can solve the problem that the static analysis method is difficult to obtain effective information details, and achieve the effect of convenient update, upgrade and expansion, efficient processing, and enhanced analysis and detection capabilities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Publication Date
- 2018-06-08
Smart Images

Figure 1 
Figure 2 
Figure 3
Abstract
Description
technical field
[0001] The invention belongs to the technical field of network security, in particular to an Android malicious application detection system based on behavior comparison of multiple operating environments. Background technique
[0002] The rapid development of the Internet today has a considerable scale. In recent years, with the rise of smart mobile terminal equipment, the mobile Internet has also developed rapidly, and smart phones and tablet computers are becoming popular in people's lives. With the gradual popularization of smart mobile terminal operating systems, the Android system platform has been welcomed by many mobile device R&D and manufacturers for its convenience and ease of use, excellent remodelability and scalability, and system open source. Gradually has a large number of system enthusiasts and user groups.
[0003] It is precisely because of the high user share of the Android system and its unique open source features that the Android syste...
Examples
Embodiment Construction
[0028] In order to make the object, technical solution and advantages of the present invention clearer, the present invention will be further described in detail below in conjunction with the accompanying drawings and exemplary embodiments. It should be understood that the exemplary embodiments described here are only used to explain the present invention, and are not intended to limit the applicable scope of the present invention.
[0029] First, the overall operation process of the Android malicious application detection system based on behavior comparison of the present invention is as follows: figure 1 shown. The four main modules drawn are information extraction module, dynamic analysis module, environment detection and confrontation module, and behavior record analysis module. The system operation scheduling module is not drawn in the flow chart. The system operation scheduling module is responsible for controlling the entire operation process during the system operatio...