Malicious application program detection method and equipment based on AI model

A technology of application programs and models, applied in the directions of instruments, electronic digital data processing, platform integrity maintenance, etc., can solve the problem of different maliciousness, difficulty in updating malicious signature database to achieve security protection effect, weak ability to learn new types of malicious detection, etc. problem, to achieve high accuracy and timeliness

Pending Publication Date: 2022-01-25
WUHAN ANTIY MOBILE SECURITY
View PDF0 Cites 2 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0003] At present, many security vendors are also investing in the field of mobile security, and the basic principle of antivirus software is to confirm the intrusion behavior by matching known malicious Trojan horse characteristics, and carry out active defense with firewalls, dynamic monitoring, etc., but the disadvantage is that it relies on malicious characteristics The update of the library, the ability to learn new malicious detection is weak
[0004] However, new malicious applications emerge in endlessly, and their maliciousness is different. Malicious detection depends on the malicious signature database. If the malicious signature database is not updated in time, it will be difficult to achieve the ideal security protection effect.

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Malicious application program detection method and equipment based on AI model
  • Malicious application program detection method and equipment based on AI model
  • Malicious application program detection method and equipment based on AI model

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0060] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are the Some, but not all, embodiments are invented. Based on the embodiments of the present invention, all other embodiments obtained by persons of ordinary skill in the art without making creative efforts belong to the protection scope of the present invention.

[0061] Aiming at the problems in the prior art, the embodiment of the present invention redesigns the algorithm on the basis of the deep learning algorithm to obtain an artificial intelligence (AI) model; The AI ​​model is trained to finally obtain the AI ​​model for malicious application detection on the Android platform. The training process includes: extracting stati...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The embodiment of the invention provides a malicious application program detection method and equipment based on an AI model. The method comprises the steps of analyzing a target file in a to-be-detected application program installation package, extracting static information in the target file, where the static information comprises at least one kind of dimension information in a behavior dimension, an authority dimension and a content dimension; processing the static information into a digital feature vector in a feature transformation mode, wherein the digital feature vector is composed of 0 and 1; inputting the digital feature vector into a trained AI model to obtain a maliciousness detection result of the to-be-detected application program; training the AI model according to the input digital feature vector, and outputting the probability that the application program corresponding to the digital feature vector is a malicious application and/or the probability that the application program corresponding to the digital feature vector is a non-malicious application. The problems of difficulty in rule extraction, low coverage, poor expansibility, easiness in bypassing and the like during traditional malicious application detection are solved, and higher accuracy and timeliness are achieved.

Description

technical field [0001] Embodiments of the present invention relate to the technical field of mobile network security, and in particular to a method and device for detecting malicious application programs based on an AI model. Background technique [0002] In the high-tech period in full swing, the development of Android software has shown explosive growth. According to the "Global Mobile Application Market Review Report 2019" released by App Annie a few days ago, the data shows that the number of global APP downloads exceeded 194 billion in 2018, a growth rate of 35% compared to 2016. Unfortunately, this popularity can also attract malware developers, pre-installed apps, bundled downloads, excessive permissions, copycat apps, etc. are hard to guard against. The prevalence of malicious applications has made users' personal privacy gradually transparent. According to the "2017Q1 China Mobile Security Market Research Report", 89.6% of the interviewed users said that they had s...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): G06F21/56
CPCG06F21/562G06F2221/033
Inventor 潘宣辰郭辰张路
Owner WUHAN ANTIY MOBILE SECURITY
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products