Software malicious behavior identification method based on ensemble learning and dynamic analysis
A technology integrating learning and identification methods, applied in the fields of information security detection and network security, can solve problems such as software difficulties, and achieve the effect of improving generalization ability and making up for code confusion.
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment
[0029] figure 1 Shown is a schematic diagram of the safety assessment model of the present invention, which mainly adopts two parts of dynamic analysis features and integrated learning training, so the present invention mainly includes the dynamic analysis stage and the behavior recognition stage.
[0030] In the dynamic analysis stage, the sandbox method is first used to simulate the operation of the software. The present invention uses the DroidBox dynamic analysis tool to run all the software data sets in a sandbox model, so as to conform to the normal use specifications as much as possible. At the same time, the monkey is used to randomly click on it to simulate the user's use, so various dynamic features can better reflect the authenticity of the software. In this way, various dynamic features such as system calls, network behaviors, taint tracking, and string operations are extracted, and each feature is explained below.
[0031] A system call is a part of the operating...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 


