Android System Malicious Application Dynamic Detection Method and System

Through Markov chain modeling and convolutional neural network model, the system call sequence features are used to solve the accuracy and complexity problems in Android malicious application detection, and efficient malicious application recognition is achieved.

CN114547605BActive Publication Date: 2025-07-29Chinese People's Liberation Army Cyberspace Force Information Engineering University
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210094057.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-26
Publication Date
2025-07-29
Estimated Expiration
2042-01-26

AI Technical Summary

Technical Problem

The existing Android malicious application detection technology has insufficient detection accuracy and computational complexity, especially the system call sequence method cannot effectively utilize the dependencies between adjacent calls, and the computational complexity is high.

Method used

By collecting system call sequences of benign and malicious applications, using Markov chain modeling and transfer probability matrix, converting them into grayscale images, and combining convolutional neural network models for feature extraction and classification, a dynamic detection system for malicious applications in Android system is constructed.

Benefits of technology

Effectively distinguish between benign and malicious applications, reduce feature dimensions, improve detection efficiency, and ensure safe and reliable operation of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114547605B_ABST
    Figure CN114547605B_ABST
Patent Text Reader

Abstract

The present invention belongs to the technical field of mobile Internet security, and particularly relates to a method and system for dynamically detecting malicious applications in the Android system. By collecting known benign applications and malicious applications, the interactive process between the host and the Android emulator is carried out using the debug bridge command, and the system call sequence features reflecting the dynamic behavior patterns of the application programs are extracted during the interactive process; and the system call sequence is regarded as a Markov chain, and the state transition probability matrix of the system call sequence is obtained by using the transition probability matrix of the Markov chain; the system call sequence state transition probability matrix is converted into a grayscale image to train the convolutional neural network model; the grayscale image of the system call sequence state transition probability matrix of the target application program is used as the input, and the target application program category is output according to the model classification result. The present invention can provide support technology for the detection of malicious application programs in the mobile Internet operating system, and can further ensure the safe and reliable operation of the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of mobile Internet security, and particularly relates to a method and system for dynamically detecting malicious applications in an Android system. Background Art

[0002] Mobile Internet operating systems benefit from a high degree of openness and can be customized and extended by installing application programs from third-party app markets, which are deeply favored by users. According to the statistics and predictions of IDC (International Data Corporation), smart phones equipped with the Android operating system will continue to lead the world in 2021, and its market share will exceed 85%. At the same time, the open system environment and the large user group have also attracted the attention of malware developers. Reports show that as of March 2020, the average number of newly added Android malware per month reached 480,000, and the privacy information security of users is facing a serious threat. Therefore, Android malicious application detection technology has emerged, aiming to perform security checks before application installation and determine whether the application is malicious. To address the challenges posed by Android malware, Google officially launched the Google Play Protect detection system for automated scanning of malware. However, according to an experiment by AV-TEST, the actual detection accuracy rate of this system for malicious applications is less than 40%. Therefore, users should not rely solely on the built-in protection programs provided by the system, but need additional detection technologies to provide more comprehensive protection for the Android system.

[0003] In recent years, the Android malicious application detection technology based on machine learning has achieved good detection results. Usually, according to the acquisition method of features used in detection, Android malicious application detection can be divided into two methods: static analysis and dynamic analysis. The static analysis method does not require actual execution of the application, but analyzes the source code of the application program, extracts information such as permissions and API (application programming interface) function calls as features, and is widely used because of its relatively fast detection speed. However, with the continuous upgrading of the means for malicious applications to evade detection, the static analysis technology has been affected by code obfuscation and strengthening, and some applications cannot obtain the source code through decompilation. Therefore, the dynamic analysis technology has emerged, complementing and supplementing each other with the static analysis technology. It analyzes and extracts the behavioral characteristics of the application by actually running the Android application program, such as network traffic information, system call sequences, etc. Among them, the system call sequence can reflect the interaction logic between the application program and the underlying system, showing the real behavior of the application program, and is the most commonly used dynamic analysis feature. Through the analysis of existing work, it is found that the current Android malicious application detection methods based on system call sequences have the following common problems: on the one hand, some research work ignores the dependency relationship between two adjacent system calls in the sequence, but statistically analyzes the occurrence frequency or permutation combination of different system calls, which weakens the application behavior characteristics hidden in the original sequence and cannot effectively distinguish between benign applications and malicious applications; on the other hand, some research work faces the problem of relatively high computational complexity. Summary of the Invention

[0004] Therefore, the present invention provides a method and system for dynamically detecting malicious applications in the Android system, effectively providing support technology for the detection of malicious application programs in the mobile Internet operating system, and ensuring the safe and reliable operation of the system.

[0005] According to the design scheme provided by the present invention, a method for dynamically detecting malicious applications in the Android system includes the following content:

[0006] Collect known benign applications and malicious applications, use the debugging bridge command to interact between the host and the Android emulator, and extract the system call sequence features used to reflect the dynamic behavior pattern of the application program during the interaction process;

[0007] Based on the Markov process, regard the system call sequence as a Markov chain, and use the transition probability matrix of the Markov chain to obtain the state transition probability matrix of the system call sequence;

[0008] Convert the system call sequence state transition probability matrix into a grayscale image, use this grayscale image as the application program fingerprint feature data sample for training the convolutional neural network model, and train the convolutional neural network model;

[0009] For the target application to be detected, use the grayscale image of its system call sequence state transition probability matrix as the input, and classify it using the trained convolutional neural network model. Output the benign or malicious category of the target application to be detected according to the classification result.

[0010] As the dynamic detection method for malicious applications in the Android system of the present invention, further, during the interaction between the host and the Android emulator, use the application automation testing tool and the system call tracking tool to obtain multiple consecutive system calls of the application, and construct the system call sequence feature of the application according to the dependency relationship between the system calls.

[0011] As the dynamic detection method for malicious applications in the Android system of the present invention, further, in extracting the system call sequence feature, first, install the application in the emulator, and then use the system call tracking tool to track the application process and record the system call sequence executed by the application; and at the same time, use the random event operation preset in the application automation testing tool to trigger the application behavior, and capture the text log storing the system call sequence, where each line in the text log records the system call operation with a time stamp; finally, construct the system call sequence feature according to the captured text log.

[0012] As the dynamic detection method for malicious applications in the Android system of the present invention, further, based on the Markov process, represent the system call sequence as X = {X m , m = 1, 2, …}, and use S = {s i , i = 0, 1, …} to represent the discrete state space of the system call sequence X, where the discrete state space is I = {1, 2, …}, and construct the state transition probability matrix of the corresponding system call sequence using the transition probability between all states.

[0013] As the dynamic detection method for malicious applications in the Android system of the present invention, further, map each element in the state transition probability matrix of the system call sequence to the interval (0, 255) to obtain the corresponding grayscale image, specifically: map the value 0 to (R: 255, G: 255, B: 255), map the value 255 to (R: 0, G: 0, B: 0), and map other values to the grayscale color (R: gray ij , G: gray ij , B: gray ij ), where gray ij = (1 - p ij ) × 255, and p ij is the transition probability between states i and j.

[0014] As the dynamic detection method for malicious applications in the Android system of the present invention, further, for grayscale images, the TF-IDF algorithm is used to rank the importance of features for all extracted system call sequences, and fingerprint feature vectors used as the input of the convolutional neural network model are selected according to the ranking results.

[0015] As the dynamic detection method for malicious applications in the Android system of the present invention, further, in the process of using the TF-IDF algorithm to rank the importance of features, system calls are regarded as terms, and the frequency of each term appearing in all documents and the inverse frequency of the documents containing the term in all documents are obtained in turn. The formula is used to obtain the TF-IDF value of the importance of system call features, and the fingerprint feature vectors are selected in descending order according to the TF-IDF values. Among them, n i is the number of times the term i appears, k is the number of documents, |D| is all documents, and |d i | is the document containing the term i.

[0016] As the dynamic detection method for malicious applications in the Android system of the present invention, further, the convolutional neural network model adopts the deep learning AlexNet model structure, and the classification result of the input is obtained by performing convolution, pooling, and fully connected operations on the input.

[0017] Further, the present invention also provides a dynamic detection system for malicious applications in the Android system, including: a data extraction module, a data processing module, a model training module, and a target detection module. Among them,

[0018] The data extraction module is used to collect known benign applications and malicious applications, use the debug bridge command to interact between the host and the Android emulator, and extract the system call sequence features used to reflect the dynamic behavior pattern of the application program during the interaction process;

[0019] The data processing module is used to regard the system call sequence as a Markov chain based on the Markov process, and use the transition probability matrix of the Markov chain to obtain the state transition probability matrix of the system call sequence;

[0020] The model training module is used to convert the system call sequence state transition probability matrix into a grayscale image, use the grayscale image as the application program fingerprint feature data sample for training the convolutional neural network model, and train the convolutional neural network model;

[0021] The target detection module is used to take the grayscale image of the system call sequence state transition probability matrix of the target application program to be detected as the input, use the trained convolutional neural network model for classification, and output the benign or malicious category of the target application program to be detected according to the classification result.

[0022] Advantages of the present invention:

[0023] Regarding the feature selection problem faced in system call sequence modeling, the present invention extracts system call sequences by analyzing the differences in system call usage patterns between benign applications and malicious applications, and obtains fingerprint features of system call sequences based on the Markov transition state matrix, retaining more complete system call dependencies while reducing the feature dimension. Further, by converting the state transition matrix into a grayscale image, the visualization of system call sequence features can be realized, and the adaptation problem between sequence fingerprint features and CNN can be solved. Regarding the training requirements for fingerprint image features, a CNN model is used to dynamically detect malicious applications in the Android system based on the fingerprint features of system call sequences, improving the detection efficiency while ensuring the dynamic detection effect. It can be applied to the detection of malicious application programs in mobile Internet operating systems such as Android, and has good application prospects. Description of the drawings

[0024] Figure 1 Schematic diagram of the process for dynamically detecting malicious applications in the Android system in the embodiment;

[0025] Figure 2 Schematic diagram of the structure of the dynamic detection framework in the embodiment;

[0026] Figure 3 Schematic diagram of an example of system call logs in the embodiment;

[0027] Figure 4 Schematic diagram of the 25 system calls with the highest usage frequencies in benign applications in the embodiment;

[0028] Figure 5 Schematic diagram of the 25 system calls with the highest usage frequencies in malicious applications in the embodiment;

[0029] Figure 6 Schematic diagram of the Mann-Whitney U test results for 102 system calls in the embodiment;

[0030] Figure 7 Schematic diagram of the calculation results of the system call sequence transition probability matrix in the embodiment;

[0031] Figure 8 Schematic diagram of the AlexNet convolutional neural network structure in the embodiment. Detailed implementation manners

[0032] To make the objectives, technical solutions, and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below in conjunction with the drawings and technical solutions.

[0033] An embodiment of the present invention provides a method for dynamically detecting malicious applications in the Android system. As shown in Figure 1 the following, it includes the following contents:

[0034] S101. Collect the known benign and malicious applications, use the debug bridge command to interact between the host and the Android emulator, and extract the system call sequence features that reflect the dynamic behavior patterns of the applications during the interaction;

[0035] S102. Based on the Markov process, regard the system call sequence as a Markov chain, and use the transition probability matrix of the Markov chain to obtain the state transition probability matrix of the system call sequence;

[0036] S103. Convert the state transition probability matrix of the system call sequence into a grayscale image, use this grayscale image as the application fingerprint feature data sample for training the convolutional neural network model, and train the convolutional neural network model;

[0037] S104. For the target application to be detected, use the grayscale image of its system call sequence state transition probability matrix as the input, classify it using the trained convolutional neural network model, and output the benign or malicious category of the target application to be detected according to the classification result.

[0038] Android system calls are mechanisms for user-level processes or application layers to request kernel-level services from the operating system, such as process management, memory management, network connection, and other access operations to hardware resources. Similar to the Linux system, the Android system also has user mode and kernel mode. When a system call is executed, the system mode switches from user mode to kernel mode, and at this time, the kernel of the operating system is allowed to perform sensitive operations. When the called system call is executed, the control right will return to user mode. An application behavior usually involves multiple consecutive system calls, and the dependency relationships between system calls form a set of system call sequences. In the embodiments of this case, as shown in Figure 2 shown, by extracting the system call sequence, constructing the system call sequence fingerprint feature, and using the convolutional neural network to perform dynamic detection of malicious applications, it can effectively provide support technology for malicious application detection in the Android system and ensure the safe and reliable operation of the system.

[0039] Further, during the interaction process between the host and the Android emulator, an application automated testing tool and a system call tracing tool are used to obtain multiple consecutive system calls of the application, and the system call sequence feature of the application is constructed based on the dependency relationship between system calls. Further, in extracting the system call sequence feature, first, install the application in the emulator, and then use the system call tracing tool to trace the application process and record the system call sequence executed by the application; and at the same time, use the random event operations preset in the application automated testing tool to trigger the application behavior, and capture the text log storing the system call sequence, where each line in the text log records the system call operation with a timestamp; finally, construct the system call sequence feature according to the captured text log.

[0040] A system call sequence is a finite list of system calls arranged in sequence at discrete times, which can be denoted as S=(c1, c2, c3, …, c n ), where c n represents the name of a single system call. The system call sequence reflects the dynamic behavior pattern of the application, and different system calls reflect different behaviors. In the embodiments of this case, the interaction between the host and the Android emulator is completed through ADB (Android Debug Bridge) commands, and the Android application automated testing tool Monkey and the system call tracing tool Strace are used together to complete the extraction of the application system call sequence. First, install the application in the Android 6.0 emulator, then use the Strace tool to trace the application process and record the system call sequence executed by the application. At the same time, execute the Monkey script in another command line, and trigger the application behavior through 500 random events composed of operations such as simulated touch, click, and swipe. At this time, the system call sequence will be saved in the form of a text log, and each line records a system call operation with a timestamp. Finally, transfer the log saved on the Android emulator side to the host system side, uninstall the application, and reset the emulator. The steps and corresponding commands for capturing the system call log are shown in Table 1:

[0041] Table 1 Steps and Commands for Extracting System Call Log

[0042]

[0043] Through the above operations, a fragment of the system call log of a certain application that can be extracted is as Figure 3As shown, each line of the log represents a system call record, which can be divided into three parts: the first part [pid 3853] indicates that the current active process number is 3853, the second part "hh:mm:ss" is the occurrence time of the system call, and the third part is the name, parameters, and return value of the system call.

[0044] In the embodiments of this case, 5560 malicious applications from the Drebin dataset and an equal number of benign applications from 360 Mobile Assistant were used to extract system call logs, constructing a sample set containing 11,120 Android application system call sequence features. The finally extracted system call sequence form can retain the name of the system call and the chronological order. A total of 102 different system calls of Android 6.0 were extracted from all samples, as shown in Table 2.

[0045] Table 2 102 system calls included in the application samples

[0046]

[0047]

[0048] Among the 102 system calls shown in Table 2, there are 25 system calls unique to benign applications, and their serial numbers are marked with (#); there are 4 system calls unique to malicious applications, and their serial numbers are marked with (*); there are 73 system calls common to both. From the above data, it can be seen that there are a large number of identical system calls between benign applications and malicious applications. To further analyze the differences in the system call usage patterns between the two, by counting the number of all system calls and sorting them according to the usage frequency, the names of the top 25 system calls and their proportions in benign applications and malicious applications are respectively as Figure 4 and Figure 5 shown. It can be observed from the figure that among the top 25 system calls with the highest usage frequencies in benign applications and malicious applications, there are still 21 system calls common to both. Therefore, to illustrate whether system calls are effective features for distinguishing malicious applications from benign applications, in the embodiments of this case, a Mann-Whitney rank sum test was performed on malicious applications and benign applications regarding system calls.

[0049] The Mann-Whitney U test is used to test whether the distribution of a certain variable is different in two independent samples. This test can compare the two groups of samples without making any distribution assumptions. The test steps are as follows:

[0050] (1) Combine the samples A with a capacity of n A and the samples B with a capacity of n B in the (n A + n B) The observed values are arranged in ascending order. Designate 1 as the rank of the smallest observed value, 2 as the rank of the second smallest observed value, and so on. If there are identical observed values, designate the rank as the average of their ordinal sums;

[0051] (2) Calculate the rank sums T A and T B ;

[0052] (3) Give the formula for the Mann - Whitney U test based on T A and T B The test statistic is shown in equations (1) - (3):

[0053] U A = n A n B + n A (n A + 1) / 2 - T A (1)

[0054] U B = n A n B + n B (n B + 1) / 2 - T B (2)

[0055]

[0056] (4) Under the set significance level α: If Z > Z α / 2 or Z ≤ -Z α / 2 , reject the null hypothesis H0.

[0057] In the embodiments of this case, the null hypothesis H0 of the Mann - Whitney U test: There is no significant difference in the system call patterns between benign applications and malicious applications; the alternative hypothesis H1: There is a significant difference in the system call patterns between benign applications and malicious applications. For a system call, if a benign or malicious application uses this system call, then the sample value is set to 1, otherwise it is set to 0. Therefore, for each system call, a vector of length 11120 will be obtained, and a total of 102 such system call feature vectors can be obtained. Plot the hypothesis test results of the corresponding system calls according to the serial numbers marked in Table 2, and the result is as shown in Figure 6 The significance level α = 0.05 is shown as the dashed line. It can be seen from the result that the p - values of 90 out of 102 system calls are less than 0.05. Therefore, there is more than 95% confidence to reject the null hypothesis H0 and accept H1, that is, there is a significant difference in the system call usage patterns between benign applications and malicious applications, which can be used as features for classification detection.

[0058] Table 3 shows the length statistics of the system call sequences of benign applications and malicious applications under various statistical parameters. It can be seen from the data in the table that there are significant differences in the lengths of the extracted system call sequences for both benign applications and malicious applications, further indicating that directly extracting sequence features using a recurrent neural network has a relatively high complexity.

[0059] Table 3 Statistical parameters of the system call sequence lengths of benign applications and malicious applications

[0060]

[0061] In a Markov chain, let X = {X i , i = 1, 2, …} be a sequence composed of random variables in a discrete-time random process, and use S = {s i , i = 0, 1, …t} to represent the discrete state space of X. If X satisfies the form in Equation (4), that is, the state at time t + 1 is only affected by the current state s t at time t and is independent of earlier states, or in other words, all the relevant information of the historical states is reflected through the current state s t , then the discrete-time random process X is said to have the Markov property, and its sequence is a Markov chain.

[0062] P(X t+1 = s|X t = s t , X t-1 = s t-1 ,..., X0 = s0) = P(X t+1 = s|X t = s t ) (4)

[0063] The system call sequence describes the running state of the system. The current system call state of the system is directly related to the previous system call. Therefore, the system call sequence can be regarded as a Markov chain.

[0064] In the transition probability, the conditional probability p ij (n) = P{X n+1 = j|X n = i} is called the transition probability of the Markov chain {X n , n ∈ T} at time n. The transition probability describes the probability of jumping from one Markov state i to the successor state j. Denote the state space as I = {1, 2, …, n}, and the transition probabilities p ij between all states form the transition probability matrix

[0065]

[0066] The transition probability matrix describes the probabilistic statistical characteristics of the evolution between the states of a Markov process, and the sum of the state transition probabilities in each row is equal to 1.

[0067] Table 4 Example of system call sequences

[0068]

[0069] Taking the system call sequence of length 10 in Table 4 as an example, the calculation result of its transition probability matrix is as Figure 7 shown.

[0070] Based on the above process, an algorithm for generating the state transition matrix of the system call sequence can be obtained, as shown in Table 5

[0071] Table 5 Algorithm for generating the transition probability matrix of system call sequences

[0072]

[0073] Furthermore, each element between (0, 1) in the obtained system call transition probability matrix is mapped to the interval (0, 255). For the convenience of observation, in the embodiments of this case, the value 0 can be mapped to white (R: 255, G: 255, B: 255), the value 255 can be mapped to black (R: 0, G: 0, B: 0), and other values are mapped to grayscale colors that transition between black and white (R: gray ij , G: gray ij , B: gray ij ):

[0074] gray ij = (1 - p ij ) × 255 (6)

[0075] According to Equation (6), the transition probability matrix can be converted into a corresponding grayscale image, which is used as the "fingerprint" feature of the application program. Generally, the fingerprint images of different applications are different. Using this feature, benign applications and malicious applications can be distinguished; the fingerprint images of malicious applications from the same family with similar malicious behaviors have a certain similarity. Using this feature, malicious applications can be classified by family.

[0076] To avoid generating too many sparse matrices when generating fingerprint map features, the importance levels of 102 system calls can be examined to screen out a relatively key set of system calls sorted by importance according to the requirements of the input layer of different neural network models. To this end, in the embodiments of this case, the TF-IDF (term frequency-inverse document frequency) algorithm is further used to sort the feature importance.

[0077] TF-IDF is commonly used in automatic text analysis in natural language processing to weigh the importance of a certain keyword. In the embodiments of this case, if a system call is regarded as a term, then TF represents the frequency of a certain term appearing in all documents, and IDF represents the inverse frequency of the document |d i |containing a certain term appearing in all documents |D|. TF-IDF is the result of multiplying the two. As shown in Equation (7), TF-IDF is proportional to the number of times a term appears in a document and inversely proportional to the number of times the word appears in the document where it is located.

[0078]

[0079] Applying the TF-IDF algorithm to sort the features of all system call sequence texts extracted in the embodiments of this case, the TF-IDF values of 102 system calls can be calculated and arranged in descending order according to the values. The TF-IDF sorting results of each system call are shown in Table 6. By retaining the first 67 system calls with TF-IDF values not less than 1e-5 as the row and column indexes of the fingerprint map matrix, a system call sequence fingerprint grayscale map with a size of 67×67 can be generated.

[0080] Table 6 TF-IDF sorting results of system calls

[0081]

[0082]

[0083] Furthermore, in the embodiments of this case, the AlexNet model structure is adopted as the convolutional neural network model to implement the detection of Android malicious applications. The Android application system call sequence fingerprint generated above is used as the model input to train the AlexNet model to obtain the final detection model. The model structure is as Figure 8 shown, which can be composed of five convolutional layers, three pooling layers and three fully connected layers. The classification result of the input is obtained by performing convolution, pooling and fully connected operations on the input. Among them, the parameter settings of the AlexNet network can be shown in Table 7.

[0084] Table 7 The 102 system calls included in the application samples

[0085]

[0086] Furthermore, based on the above method, an embodiment of the present invention further provides an Android system malicious application dynamic detection system, including: a data extraction module, a data processing module, a model training module, and a target detection module II, where

[0087] The data extraction module is used to collect known benign applications and malicious applications, use the debugging bridge command to interact between the host and the Android emulator, and extract the system call sequence features for reflecting the dynamic behavior patterns of the application during the interaction;

[0088] The data processing module is used to regard the system call sequence as a Markov chain based on the Markov process, and use the transition probability matrix of the Markov chain to obtain the state transition probability matrix of the system call sequence;

[0089] The model training module is used to convert the system call sequence state transition probability matrix into a grayscale image, use the grayscale image as the application fingerprint feature data sample for training the convolutional neural network model, and train the convolutional neural network model;

[0090] The target detection module is used to take the grayscale image of the system call sequence state transition probability matrix of the target application to be detected as the input, use the trained convolutional neural network model for classification, and output the benign or malicious category of the target application to be detected according to the classification result.

[0091] Unless otherwise specifically stated, the relative steps, numerical expressions, and values of the components and steps set forth in these embodiments do not limit the scope of the present invention.

[0092] Based on the above method and / or system, an embodiment of the present invention further provides a server, including: one or more processors; a storage device for storing one or more programs, and when the one or more programs are executed by the one or more processors, the one or more processors implement the above method.

[0093] Based on the above method and / or system, an embodiment of the present invention further provides a computer-readable medium, on which a computer program is stored, and when the program is executed by a processor, the above method is implemented.

[0094] In all the examples shown and described here, any specific value should be construed as merely exemplary, not as a limitation. Therefore, other examples of the exemplary embodiments may have different values.

[0095] It should be noted that like reference numerals and letters refer to like items in the following figures, and thus, once an item is defined in one figure, it need not be further defined or explained in subsequent figures.

[0096] Finally, it should be noted that the above-described embodiments are only specific embodiments of the present invention, which are used to illustrate the technical solutions of the present invention, rather than to limit it. The protection scope of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: any person skilled in the art within the technical scope disclosed by the present invention can still modify the technical solutions described in the foregoing embodiments or can easily conceive of changes, or make equivalent replacements for some of the technical features; and these modifications, changes or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be determined by the protection scope of the claims.

Claims

1. A dynamic detection method for malicious Android applications, characterized in that, It includes the following content: Collect known benign and malicious applications, use debug bridge commands to interact between the host and the Android emulator, and extract system call sequence features that reflect the dynamic behavior patterns of applications during the interaction; Based on the Markov process, the system call sequence is regarded as a Markov chain, and the state transition probability matrix of the system call sequence is obtained by using the transition probability matrix of the Markov chain. Specifically, based on the Markov process, the system call sequence is represented as X = {X m ,m=1,2,...},with S={S i ,i=0,1,...} represents the discrete state space of the system call sequence X. The discrete state space is I={1,2,...,}. The state transition probability matrix of the corresponding system call sequence is constructed using the transition probabilities between all states; Convert the system call sequence state transition probability matrix into a grayscale image, use this grayscale image as the application fingerprint feature data sample for training the convolutional neural network model, and train the convolutional neural network model; among them, map each element in the state transition probability matrix of the system call sequence to the interval (0, 255) to obtain the corresponding grayscale image. Specifically: map the value 0 to (R: 255, G: 255, B: 255), map the value 255 to (R: 0, G: 0, B: 0), and map other values to grayscale color (R: gray ij , G: gray ij , B: gray ij ), where gray ij (= 1 - p ij ) × 255, p ij is the transition probability between states i and j; For the target application to be detected, use the grayscale image of its system call sequence state transition probability matrix as input, classify it using the trained convolutional neural network model, and output the benign or malicious category of the target application to be detected according to the classification result.

2. The dynamic detection method for malicious Android applications according to claim 1, characterized in that, During the interaction between the host and the Android emulator, use application automation testing tools and system call tracking tools to obtain multiple consecutive system calls of the application, and construct the system call sequence features of the application based on the dependency relationship between system calls.

3. The dynamic detection method for malicious Android applications according to claim 1 or 2, characterized in that, When extracting system call sequence features, first, install the application in the emulator, then use the system call tracking tool to track the application process and record the system call sequence executed by the application; at the same time, trigger the application behavior using the preset random event operations in the application automation testing tool, and capture the text log storing the system call sequence. Each line in the text log records the system call operation with a timestamp; finally, construct the system call sequence features based on the captured text log.

4. The dynamic detection method for malicious Android applications according to claim 1, characterized in that, For the grayscale image, use the TF-IDF algorithm to sort the importance of all extracted system call sequences, and select the fingerprint feature vector as the input of the convolutional neural network model according to the sorting result.

5. The dynamic detection method for malicious Android applications according to claim 4, characterized in that In the process of using the TF-IDF algorithm to sort feature importance, taking system calls as terms, successively obtaining the frequency of each term appearing in all documents and the inverse frequency of the documents containing the term in all documents, and using the formula to obtain the TF-IDF value of the feature importance of system calls, and sorting in descending order according to the TF-IDF value to select the fingerprint feature vector. Among them, n i is the number of times the term i appears, k is the number of documents, |D| is all documents, and |d i | is the document containing the term i.

6. The dynamic detection method for malicious Android applications according to claim 1, characterized in that The convolutional neural network model adopts the deep learning AlexNet model structure, and obtains the classification result of the input through convolution, pooling, and fully connected operations on the input.

7. A dynamic detection system for malicious Android applications, characterized in that It includes: a data extraction module, a data processing module, a model training module, and a target detection module, where The data extraction module is used to collect known benign and malicious applications, use debug bridge commands to interact between the host and the Android emulator, and extract system call sequence features that reflect the dynamic behavior patterns of applications during the interaction; A data processing module, which is used to regard the system call sequence as a Markov chain based on the Markov process, and utilize the transition probability matrix of the Markov chain to obtain the state transition probability matrix of the system call sequence; specifically: based on the Markov process, represent the system call sequence as X = {X m , m = 1, 2,...}, and use S = {S i , i = 0, 1,...} to represent the discrete state space of the system call sequence X. The discrete state space is I = {1, 2,...}, and construct the corresponding state transition probability matrix of the system call sequence by using the transition probabilities between all states; A model training module, which is used to convert the system call sequence state transition probability matrix into a grayscale image, use the grayscale image as an application fingerprint feature data sample for training a convolutional neural network model, and train the convolutional neural network model; wherein, each element in the state transition probability matrix of the system call sequence is mapped to the interval (0, 255) to obtain the corresponding grayscale image. Specifically: map the value 0 to (R: 255, G: 255, B: 255), map the value 255 to (R: 0, G: 0, B: 0), and map other values to the grayscale color (R: gray ij , G: gray ij , B: gray ij ), where gray ij (= 1 - p ij ) × 255, and p ij is the transition probability between states i and j. The target detection module is used to, for the target application to be detected, use the grayscale image of its system call sequence state transition probability matrix as input, classify it using the trained convolutional neural network model, and output the benign or malicious category of the target application to be detected according to the classification result.

8. A computer-readable storage medium, in which one or more instructions are stored, and when the one or more instructions are executed by a processor, the method described in any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Intelligent terminal malicious software dynamic detection method based on system call

    CN109753801A

  • Malicious code detection method based on system behavior sequence

    CN110263538A