A software detection method, system, device and medium for Android platform

By building a malware prediction model based on bidirectional long and short-term recurrent network and text convolutional network, the problems of low detection efficiency and poor accuracy of traditional detection methods are solved, and more efficient and accurate malware detection is achieved.

CN119312329BActive Publication Date: 2025-05-27WUHAN TIANCHENG CENTURY TECHNOLOGY CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411370879.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-29
Publication Date
2025-05-27
Estimated Expiration
2044-09-29

AI Technical Summary

Technical Problem

In the face of the rapid development of malware, traditional malware detection methods are inefficient in the detection and are vulnerable to malware evasion technology attacks, resulting in low accuracy of detection results.

Method used

By obtaining the original application data of Android security software and malware, building a training set, and building an initial prediction model based on the preset two-way long and short-term recurrent network and text convolutional network, the initial prediction model is trained using the training set to obtain the target malware prediction model, and then detect the Android software to be tested.

Benefits of technology

Improves the accuracy and efficiency of malware detection, enables the evasion technology that can identify trained Android malware, and enhances adaptability to new and mutant malware.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119312329B_ABST
    Figure CN119312329B_ABST
Patent Text Reader

Abstract

The present application relates to a software detection method, system, device and medium for an Android platform, the method comprising: obtaining the original application data of Android security software and Android malware; obtaining a training set based on the original application data; constructing an initial prediction model based on a preset bidirectional long-short term recurrent network and a preset text convolutional network; training the initial prediction model using the training set to obtain a target malware prediction model; obtaining the application data of the Android software to be tested, and processing the application data to be tested based on the target malware detection model to obtain the prediction result of the Android software to be tested. The method solves the problem that with the rapid development of malware technology, the detection efficiency of traditional malware detection methods is low, and they are vulnerable to malware evasion technology attacks, resulting in low accuracy of detection results.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] In the process of the widespread popularity of smartphones, the Android platform has become one of the most popular mobile operating systems globally due to its openness. As users' dependence on Android devices increases day by day, malware poses a serious threat to users' privacy and device security. These malware usually implant malicious code by tampering with application (APK) files, thereby achieving the purpose of stealing data, remote control, and even damaging the device.

[0003] Traditional malware detection technologies mainly rely on methods such as signature matching and behavior analysis. However, with the rapid development of malware technologies, when traditional malware detection methods detect malware, they are vulnerable to malware evasion technology attacks, resulting in not only low detection efficiency but also affecting the accuracy of detection results. For example, through technologies such as dynamic code loading, encryption, and obfuscation, malware can effectively evade static feature-based detection systems. Summary of the Invention

[0004] In order to overcome the problems that with the rapid development of malware technologies, the detection efficiency of traditional malware detection methods is low, vulnerable to malware evasion technology attacks, and resulting in low accuracy of detection results, this application provides a software detection method, system, device, and medium for the Android platform.

[0005] In the first aspect, to solve the above technical problems, this application provides a software detection method for the Android platform, including:

[0006] Obtain the original application data of Android security software and Android malware;

[0007] Obtain a training set based on the original application data;

[0008] Based on a preset bidirectional long short-term recurrent network and a preset text convolutional network, construct an initial prediction model;

[0009] Train the initial prediction model using the training set to obtain a target malware prediction model;

[0010] Obtain the test application data of the Android software to be tested, and process the test application data based on the target malware detection model to obtain the prediction result of the Android software to be tested.

[0011] In the second aspect, this application also provides a software detection system for the Android platform, including:

[0012] An acquisition module, configured to obtain the original application data of Android security software and Android malware;

[0013] The first obtaining module is configured to obtain a training set based on the original application data;

[0014] The constructing module is configured to construct an initial prediction model based on a preset bidirectional long short-term memory network and a preset text convolutional network;

[0015] The training module is configured to train the initial prediction model by using the training set to obtain a target malware prediction model;

[0016] The second obtaining module is configured to obtain the to-be-tested application data of the to-be-tested Android software, and process the to-be-tested application data based on the target malware detection model to obtain a malicious prediction result of the to-be-tested Android software.

[0017] In a third aspect, the present application further provides a computing device, including a memory, a processor, and a program stored on the memory and running on the processor. When the processor executes the program, the steps of a software detection method for an Android platform as described above are implemented.

[0018] In a fourth aspect, the present application further provides a computer-readable storage medium. Instructions are stored in the computer-readable storage medium. When the instructions run on a terminal device, the terminal device is caused to execute the steps of a software detection method for an Android platform.

[0019] The beneficial effects of the present application are as follows: A training set is constructed through the original application data of Android security software and security malware, and an initial prediction model is constructed based on a preset bidirectional long short-term memory network and a preset text convolutional network, and the initial prediction model is trained by using the training set to obtain a target malware prediction model. In this way, since the training set contains data samples of Android security software and security malware, the data samples in the training set are sufficiently rich, which can deepen the training degree of the initial prediction model to improve the objectivity of model training, thereby improving the accuracy of the trained target malware prediction model. Then, the target malware prediction model is used to automatically identify and process the to-be-tested application data of the to-be-tested Android software, which can not only improve the detection efficiency, but also identify the application data of the trained Android malware, avoiding being attacked by the evasion technology of the trained Android malware, thereby improving the accuracy of the detection result. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] Figure 1 It is a schematic flowchart of a software detection method for an Android platform shown in an exemplary embodiment of the present application;

[0021] Figure 2 It is a schematic structural diagram of a software detection system for an Android platform shown in an exemplary embodiment of the present application. DETAILED DESCRIPTION

[0022] The following embodiments are further explanations and supplements to this application and do not impose any restrictions on this application.

[0023] The following describes a software detection method, system, device, and medium for an Android platform according to an embodiment of this application with reference to the accompanying drawings.

[0024] A software detection method for an Android platform according to an embodiment of this application. This method is applied to a terminal device. In the solution of this application, the terminal device is used as the execution subject to illustrate the solution of this application. The terminal device is used to execute the steps of a software detection method for an Android platform.

[0025] Please refer to Figure 1 , Figure 1 , which shows a software detection method for an Android platform according to an exemplary embodiment of this application. As Figure 1 shown, this application provides a software detection method for an Android platform, including:

[0026] Step S11: Obtain the original application data of Android security software and Android malware.

[0027] Step S12: Obtain a training set based on the original application data.

[0028] Step S13: Based on a preset bidirectional long short-term recurrent network and a preset text convolutional network, construct an initial prediction model.

[0029] Step S14: Use the training set to train the initial prediction model to obtain a target malware prediction model.

[0030] Step S15: Obtain the test application data of the Android software to be tested, and process the test application data based on the target malware detection model to obtain the prediction result of the Android software to be tested.

[0031] A software detection method for an Android platform of the present embodiment, a training set is constructed by the original application data of Android security software and security malware, and an initial prediction model is constructed based on a preset bidirectional long-short term recurrent network and a preset text convolutional network, and the initial prediction model is trained using the training set to obtain a target malware prediction model. In this way, since the training set contains data samples of Android security software and security malware, the data samples in the training set are rich enough to deepen the training degree of the initial prediction model, so as to improve the objectivity of the model training, thereby improving the accuracy of the trained target malware prediction model. Then, the target malware prediction model is used to automatically identify and process the application data to be tested of the Android software to be tested, which can not only improve the detection efficiency, but also identify the application data of the trained Android malware, avoid being attacked by the evasion technology of the trained Android malware, thereby improving the accuracy of the detection result. At the same time, the method of the present embodiment can also identify the application data of the problem software with code obfuscation problems, and the prediction results of the target malware detection model include malware, error software and security software.

[0032] In this embodiment, the bidirectional long short-term recurrent network (Bidirectional Long Short-Term Memory, Bi-LSTM) is a special recurrent neural network (Recurrent Neural Network, RNN) structure, which is widely used in sequence data processing, especially in the field of natural language processing (Natural Language Parsing, NLP). Bi-LSTM processes data by combining two independent LSTM (Long Short-Term Memory, recurrent neural network) layers, which transmit and learn information along the forward and reverse directions of the time series respectively. This structure enables the network to obtain past and future context information at each time point.

[0033] The Text Convolutional Neural Network (TextCNN) consists of a word embedding layer, a convolutional layer, an activation layer, a pooling layer, a fully connected layer, and an output layer. Among them, the word embedding layer is used to convert the input text data into vectors with a fixed dimension between 50 and 300. The convolutional layer uses multiple convolutional kernels of different sizes on top of the word embedding layer to extract local features in the text data. Each convolutional kernel slides on the embedding matrix of the text data, extracts and generates new feature maps, and then is followed by an activation layer to enhance the network's non-linear ability. Then, the pooling layer is used to downsample the feature maps generated by the convolutional layer. Finally, the fully connected layer is used for output classification. The structure of the text convolutional network is simple and efficient, especially effective in short text classification tasks such as sentiment analysis and topic classification. And due to its parallel processing characteristics, it shows high performance when dealing with large-scale data, can effectively improve the accuracy of training the model using an opcode training set, and then through parameter tuning and verification of the prediction model, more accurate detection of Android applications that are changing rapidly in the market can be achieved.

[0034] Generally, for the text convolutional network, when the number of samples in the training set used for training is less than a preset amount or the training task is relatively simple, the word embedding layer is set to convert to dimensions of 50, 100, or 128. When the number of samples in the training set is greater than or equal to a preset amount or the training task is relatively complex, the word embedding layer is set to convert to dimensions of 200, 256, or 300. In this embodiment, the word embedding layer is set to convert to a dimension of 256.

[0035] Optionally, obtaining the original application data corresponding to Android security software and Android malware includes:

[0036] Obtaining Android security software and Android malware from a preset Android software dataset;

[0037] Performing reverse engineering on each Android software in the Android security software and Android malware to obtain initial code;

[0038] Performing decompilation processing on the initial code to obtain target format code;

[0039] Performing opcode extraction on the target format code to obtain intermediate layer opcodes and native code opcodes;

[0040] Obtaining the original application data based on the intermediate layer opcodes and native code opcodes.

[0041] In this embodiment, the Android software dataset (Androzoo) is a foreign Android application dataset. It uses crawlers to crawl the Android security software data from the Android application store and the Android malware data from the VirusTotal website. Among them, the Android security software data and the Android malware data are stored in the APK (Android Package, machine program) structure in the APK file. Virustotal is a website that provides malware samples and is used to obtain typical Android malware samples.

[0042] Therefore, the Android security software and Android malware obtained from the preset Android software dataset in this embodiment can cover most of the Android software samples on the market, ensuring the richness of the sample quantity in the training set obtained from the original application data of the Android security software and Android malware, so as to improve the training depth of the subsequent initial prediction model, thereby improving the training accuracy of the initial prediction model. At the same time, the Apktool tool and the IDA pro tool are used to perform reverse engineering on each Android software in the Android security software and Android malware to deduce the implementation logic of each Android software and obtain the initial code corresponding to the implementation logic. Here, the Apktool and IDA pro tools perform two types of data extraction work. The apktool tool performs the extraction of the initial intermediate layer opcodes, while the IDA pro performs the extraction of the initial native code opcodes. And the initial code is decompiled to adjust the format of the initial code to the target format code that can be recognized by the subsequent initial prediction model, that is, the text format code. Then, since the APK file contains smali code files and.so files, the smali files contain the intermediate layer opcodes / smali opcodes of the software compiled by the Dalvik virtual machine, and the.so files contain the native code (native code) opcodes / local code opcodes / arm assembly language of the software. Therefore, by extracting the opcodes from the target format code, the intermediate layer opcodes and the native code opcodes can be directly extracted, and the data in the two modalities of the intermediate layer opcodes and the native code opcodes are used as the data in the original application data, which is convenient for performing malicious analysis at different levels on the Android software during the subsequent training process, further improving the training accuracy of the initial prediction model, enabling the trained target malware prediction model to contain a more accurate generalization of the global situation of Android applications, and thus improving the prediction accuracy of the target malware prediction model for the software to be tested.

[0043] Among them, smali code is an assembly language for Android Dalvik to execute bytecodes. Smali is a medium between the Java language and the Dalvik virtual machine, equivalent to a generalization of high-level languages such as Java or Kotlin in the program.

[0044] Optionally, a training set is obtained based on the original application data, including:

[0045] Preprocess the original application data to obtain intermediate application data; wherein, the preprocessing includes mapping processing and cleaning processing;

[0046] Perform data dimensionality reduction on the intermediate application data to obtain target training data;

[0047] Form a training set based on the target training data.

[0048] In this embodiment, a preset Python automation script is used to perform preprocessing such as mapping processing and cleaning processing on the original application data, which can screen out illegal data (error data) and abnormal data (all-zero data) in the original application data, and can also analyze more useful information data and data that has a greater impact on prediction. Then, data dimensionality reduction is performed on the intermediate application data obtained by preprocessing to obtain target training data that is convenient for the initial prediction model to recognize, so as to improve the training efficiency of the initial prediction model.

[0049] In this embodiment, the TF-IDF (Term Frequency-Inverse Document Frequency) method is used to perform data dimensionality reduction on the intermediate application data obtained by preprocessing. The TF-IDF method is a widely used weight calculation method in text mining and information retrieval, which is used to evaluate the importance of a word for a document set or a single document in a corpus. Its idea is based on the fact that if a certain word appears frequently in an article and rarely appears in other articles, then this word is considered to have good category discrimination ability and is an important word in this article. The target training data obtained by data dimensionality reduction through the TF-IDF method can better summarize the code call information of Android software, thereby further improving the training accuracy of the initial prediction model.

[0050] Optionally, use the training set to train the initial prediction model to obtain a target malware prediction model, including:

[0051] Input the training set into the initial prediction model, and use the training samples in the training set to train the bidirectional long short-term recurrent network and the text convolutional network to obtain the trained initial prediction model;

[0052] Based on the test samples in the training set and the trained initial prediction model, obtain a target malware prediction model.

[0053] In this embodiment, the bidirectional long short-term recurrent network and the text convolutional network in the initial prediction model are initially trained using the training samples in the training set to obtain the trained initial prediction model, and based on the test samples in the training set and the trained initial prediction model, a target malware prediction model is obtained. In this way, by training the model in batches using the training samples and the test samples, the training workload for each time can be reduced, and the slow operation of the training system caused by excessive training workload during the training process can be avoided, thereby improving the efficiency of model training. Among them, the training set includes a training sample set, a test sample set, and a validation sample set, and the validation samples in the validation sample set are used to verify the prediction accuracy of the trained target malware detection model. By randomly dividing the data in the training set into a training sample set, a test sample set, and a validation sample set, the randomness and objectivity of the data in each set can be ensured, human factors can be reduced, and the accuracy of the target malware detection model can be effectively improved.

[0054] Optionally, obtaining a target malware prediction model based on the test samples in the training set and the trained initial prediction model includes:

[0055] Testing the trained initial model using the test samples in the training set to obtain test results;

[0056] Based on the matching result between the test result and the corresponding true result, obtaining the first accuracy rate of the trained initial prediction model;

[0057] Based on the first accuracy rate, obtaining a target malware prediction model.

[0058] In this embodiment, by obtaining the matching result between the test result obtained by testing the trained initial model using the test samples in the training set and the corresponding true result, the first accuracy rate of the trained initial prediction model can be obtained, so as to know whether the trained initial prediction model meets the accuracy requirements, and based on the first accuracy rate, a target malware prediction model is obtained, so that the target malware prediction model can meet the accuracy requirements, thereby improving the accuracy of the detection result output by the target malware prediction model. Among them, the calculation method of the first accuracy rate is the number of successful matches divided by the number of test samples, usually expressed in the mathematical form of a percentage.

[0059] Optionally, obtaining a target malware prediction model based on the first accuracy rate includes:

[0060] When the first accuracy rate is greater than or equal to the preset value, using the trained initial prediction model as the target malware prediction model;

[0061] When the first accuracy rate is less than the preset value, performing iterative training on the trained initial prediction model for a preset number of times to obtain an iterated prediction model;

[0062] Obtain the second accuracy rate of the iterated prediction model. If the second accuracy rate is greater than or equal to the preset value, then use the iterated prediction model as the target malware prediction model;

[0063] If the second accuracy rate is less than the preset value, continuously perform iterative training on the iterated prediction model for a preset number of times until the corresponding accuracy rate is greater than or equal to the preset value, and then obtain the target malware prediction model.

[0064] In this embodiment, based on the first accuracy rate, it can be known whether the trained initial prediction model meets the accuracy requirement. That is, when the first accuracy rate is greater than or equal to the preset value, it indicates that the trained initial prediction model meets the accuracy requirement, and then the trained initial prediction model is used as the target malware prediction model, so that the accuracy of the target malware prediction model during prediction can meet the requirement. When the first accuracy rate is less than the preset value, it indicates that the trained initial prediction model does not meet the accuracy requirement, and then iterative training is performed on the trained initial prediction model until the accuracy rate of the trained model is greater than or equal to the preset value, and then the model with the accuracy rate greater than or equal to the preset value is used as the target malware prediction model, so that the accuracy of the target malware prediction model during prediction can meet the requirement.

[0065] In this embodiment, when the second accuracy rate of the iterated prediction model is less than the preset value, the training samples, test samples, and validation samples in the training set are re-divided, and the iterated prediction model is successively iteratively trained using the training samples and test samples for a preset number of times. If the corresponding accuracy rate is less than the preset value, the training samples, test samples, and validation samples in the training set are re-divided again and iterative training is performed accordingly until the corresponding accuracy rate is greater than or equal to the preset value.

[0066] In each iterative training in this embodiment, the grid search method or the manual parameter tuning method is used to perform parameter tuning and verification on the training model. Among them, Grid Search: systematically traverses various parameter combinations in the model to find the best parameter configuration combination. Manual parameter tuning: first determine the parameter ranges of the respective parameters to be adjusted in the model, and according to the principle of controlling variables, conduct multiple experiments to find the best configuration combination of the respective parameters to be adjusted in the model. For example, for Bi-LSTM, the parameters to be adjusted include the hidden layer size, learning rate, and batch size.

[0067] Optionally, based on the target malware detection model, process the data of the application to be tested to obtain the malicious prediction result of the Android software to be tested, including:

[0068] Preprocess the data of the application to be tested to obtain the intermediate data to be tested;

[0069] Perform data dimensionality reduction on the intermediate data to be measured to obtain the target data to be measured;

[0070] Input the target data to be measured into the target malware detection model, and use the bidirectional long short-term recurrent network and text convolutional network of the target malware detection model to process the target data to be measured respectively, to obtain a first result and a second result;

[0071] Perform voting method integration on the first result and the second result to obtain the prediction result of the Android software to be measured.

[0072] In this embodiment, the bidirectional long short-term recurrent network and text convolutional network of the target malware detection model are used to process the target data to be measured that is convenient for the target malware detection model to identify after preprocessing and data dimensionality reduction respectively, to achieve double recognition of the target data to be measured, and obtain a first result and a second result. And perform voting method integration on the first result and the second result. Compared with using only the bidirectional long short-term recurrent network or text convolutional network to perform single recognition processing on the target data to be measured, the method of this embodiment has undergone double recognition, that is, only when both the first result and the second result are safe software, the prediction result of the target malware detection model is safe software, so as to further improve the prediction accuracy of the target malware detection model.

[0073] Voting method integration uses the Ensemble Learning method. Ensemble Learning is a powerful methodology in machine learning. It solves a single prediction problem by constructing and combining multiple learners to achieve better prediction performance than a single model. The basic idea of Ensemble Learning is that the overall effect of combining multiple learners is usually better than the effect of any single learner.

[0074] This application uses a bidirectional long short-term recurrent network (Bi-LSTM) and a text convolutional network (TextCNN) to perform feature learning and classification on the application data of Android software. Bi-LSTM can capture the context dependencies in the opcode sequence, while TextCNN automatically extracts features in the local area using the convolutional layer. By effectively integrating the learning results of these two models, not only the accuracy of Android malware detection is improved, but also the adaptability of the trained target malware prediction model to new and variant malware is enhanced, overcoming the limitations of traditional methods in dealing with complex and mutated malicious codes.

[0075] Please refer to Figure 2 , Figure 2 which shows a software detection system for an Android platform shown in an exemplary embodiment of this application. As Figure 2 shown, this application provides a software detection system for an Android platform, including:

[0076] An acquisition module, configured to acquire the original application data of Android security software and Android malware;

[0077] A first obtaining module, configured to obtain a training set based on the original application data;

[0078] A construction module, configured to construct an initial prediction model based on a preset bidirectional long short-term recurrent network and a preset text convolutional network;

[0079] A training module, configured to train the initial prediction model using the training set to obtain a target malware prediction model;

[0080] A second obtaining module, configured to obtain the to-be-tested application data of the to-be-tested Android software, and process the to-be-tested application data based on the target malware detection model to obtain a malicious prediction result of the to-be-tested Android software.

[0081] In a software detection system for an Android platform according to this embodiment, the original application data of Android security software and security malware acquired by the acquisition module is used to construct a training set in the first obtaining module, and an initial prediction model is constructed by the construction module based on a preset bidirectional long short-term recurrent network and a preset text convolutional network, and the initial prediction model is trained using the training set in the training module to obtain a target malware prediction model. In this way, since the training set contains data samples of Android security software and security malware, the data samples in the training set are sufficiently rich, which can deepen the training degree of the initial prediction model to improve the objectivity of model training, thereby improving the accuracy of the trained target malware prediction model. Then, in the second obtaining module, the target malware prediction model is used to automatically identify and process the to-be-tested application data of the to-be-tested Android software, which can not only improve the detection efficiency, but also identify the application data of the trained Android malware, avoiding being attacked by the evasion technology of the trained Android malware, thereby improving the accuracy of the detection result.

[0082] Optionally, the acquisition module is specifically configured to:

[0083] Acquire Android security software and Android malware from a preset Android software dataset;

[0084] Perform reverse engineering on each Android software in the Android security software and Android malware to obtain initial code;

[0085] Perform decompilation processing on the initial code to obtain target format code;

[0086] Extract operation codes from the target format code to obtain intermediate layer operation codes and native code operation codes;

[0087] Obtain the original application data based on the intermediate layer operation codes and the native code operation codes

[0088] Optionally, the first obtaining module is specifically configured to:

[0089] Preprocess the original application data to obtain intermediate application data;

[0090] Reduce the dimension of the intermediate application data to obtain target training data;

[0091] Form a training set based on the target training data.

[0092] Optionally, the training module is specifically configured to:

[0093] Input the training set into the initial prediction model, and use the training samples in the training set to train the bidirectional long short-term recurrent network and the text convolutional network to obtain the trained initial prediction model;

[0094] Based on the test samples in the training set and the trained initial prediction model, obtain the target malware prediction model.

[0095] Optionally, the training module is specifically configured to:

[0096] Use the test samples in the training set to test the trained initial model to obtain test results;

[0097] Based on the matching result between the test result and the corresponding true result, obtain the first accuracy rate of the trained initial prediction model;

[0098] Based on the first accuracy rate, obtain the target malware prediction model.

[0099] Optionally, the training module is specifically configured to:

[0100] When the first accuracy rate is greater than or equal to the preset value, use the trained initial prediction model as the target malware prediction model;

[0101] When the first accuracy rate is less than the preset value, perform iterative training on the trained initial prediction model for a preset number of times to obtain the iterated prediction model;

[0102] Obtain the second accuracy rate of the iterated prediction model. If the second accuracy rate is greater than or equal to the preset value, use the iterated prediction model as the target malware prediction model;

[0103] If the second accuracy rate is less than the preset value, continuously perform iterative training on the iterated prediction model for a preset number of times until the corresponding accuracy rate is greater than or equal to the preset value to obtain the target malware prediction model.

[0104] Optionally, the second obtaining module is specifically configured to:

[0105] Preprocess the application data to be tested to obtain intermediate data to be tested;

[0106] Perform data dimensionality reduction on the intermediate data to be tested to obtain target data to be tested;

[0107] Input the target data to be tested into the target malware detection model, and use the bidirectional long short-term recurrent network and text convolutional network of the target malware detection model to process the target data to be tested respectively to obtain a first result and a second result;

[0108] Integrate the first result and the second result by voting to obtain the prediction result of the Android software to be tested.

[0109] A computing device according to an embodiment of the present application includes a memory, a processor, and a program stored on the memory and running on the processor. When the processor executes the program, it implements some or all of the steps of the above software detection method for an Android platform.

[0110] Among them, the computing device can be a computer. Correspondingly, its program is computer software, and the above parameters and steps in a computing device of the present application can refer to the parameters and steps in the embodiments of the software detection method for an Android platform in the foregoing text, which will not be elaborated here.

[0111] A computer-readable storage medium according to an embodiment of the present application stores instructions therein. When the instructions are running, they execute the steps of the above software detection method for an Android platform.

[0112] Among them, the computer-readable storage medium can be a transient computer-readable storage medium or a non-transient computer-readable storage medium.

[0113] The technical solution of the embodiment of the present disclosure can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes one or more instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method of the embodiment of the present disclosure. The foregoing computer-readable storage medium can be a non-transient computer-readable storage medium, including: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes, or can also be a transient computer-readable storage medium.

[0114] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. Each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the above-mentioned module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the block may occur in a different order from that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, as well as the combination of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0115] Those skilled in the art know that the present application can be implemented as a system, a method, or a computer program product. Therefore, the present disclosure can be specifically implemented in the following forms: it can be completely hardware, can also be completely software (including firmware, resident software, microcode, etc.), or can also be in the form of a combination of hardware and software, which is generally referred to as a "module" or "system" in this article. In addition, in some embodiments, the present application can also be implemented in the form of a computer program product in one or more computer-readable media, and the computer-readable media contains computer-readable program code. Computer-readable storage media can be, for example, but not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination of the above.

[0116] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples", etc. means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.

[0117] Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present application. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present application.

Claims

1. A software detection method for an Android platform, characterized in that: include: Get Android security software and Android malware from a pre-set Android software dataset; Reverse engineering each Android software in the Android security software and the Android malware to obtain an initial code; Decompiling the initial code to obtain a target format code; Extracting the operation code from the target format code to obtain the intermediate layer operation code and the native code operation code; Obtaining original application data based on the intermediate layer opcode and the native code opcode; Preprocessing the original application data to obtain intermediate application data, wherein the preprocessing includes mapping processing and cleaning processing; using the TF-ID method to reduce the dimension of the intermediate application data, extracting important words in the intermediate application data, and obtaining target training data, wherein the important words have the ability to distinguish categories; forming a training set based on the target training data; Based on the preset bidirectional long short-term recurrent network and the preset text convolutional network, an initial prediction model is constructed; Using the training set to train the initial prediction model to obtain a target malware prediction model; The application data to be tested of the Android software to be tested is obtained, and the application data to be tested is processed based on the target malware detection model to obtain a prediction result of the Android software to be tested; wherein the processing is to use the bidirectional long short-term recurrent network and the text convolutional network of the target malware detection model to process the target data to be tested respectively, and the first result and the second result obtained by the processing are integrated by voting.

2. The method according to claim 1, characterized in that The using the training set to train the initial prediction model to obtain a target malware prediction model includes: Inputting the training set into the initial prediction model, and using the training samples in the training set to train the bidirectional long short-term recurrent network and the text convolutional network to obtain a trained initial prediction model; A target malware prediction model is obtained based on the test samples in the training set and the trained initial prediction model.

3. The method according to claim 2, characterized in that The step of obtaining a target malware prediction model based on the test samples in the training set and the trained initial prediction model includes: Using the test samples in the training set to test the trained initial model to obtain a test result; Based on the matching result between the test result and the corresponding true result, obtaining a first accuracy rate of the trained initial prediction model; Based on the first accuracy rate, a target malware prediction model is obtained.

4. The method according to claim 3, characterized in that The step of obtaining a target malware prediction model based on the first accuracy rate includes: When the first accuracy rate is greater than or equal to a preset value, using the trained initial prediction model as a target malware prediction model; When the first accuracy rate is less than the preset value, performing a preset number of iterative training on the trained initial prediction model to obtain an iterative prediction model; Obtaining a second accuracy rate of the iterated prediction model, and if the second accuracy rate is greater than or equal to the preset value, using the iterated prediction model as a target malware prediction model; If the second accuracy rate is less than the preset value, the iterative prediction model is continuously trained for the preset number of times until the corresponding accuracy rate is greater than or equal to the preset value, thereby obtaining a target malware prediction model.

5. The method according to any one of claims 1 to 4, characterized in that: The processing of the application data to be tested based on the target malware detection model to obtain a malicious prediction result of the Android software to be tested includes: Preprocessing the application data to be tested to obtain intermediate data to be tested; Performing data dimension reduction on the intermediate data to be tested to obtain target data to be tested; Inputting the target data to be tested into the target malware detection model, and using the bidirectional long short-term recurrent network and the text convolutional network of the target malware detection model to process the target data to be tested respectively to obtain a first result and a second result; The first result and the second result are integrated by voting to obtain a prediction result of the Android software to be tested.

6. A software detection system for an Android platform, characterized in that: include: An acquisition module, used for acquiring Android security software and Android malware from a preset Android software dataset; Reverse engineering each Android software in the Android security software and the Android malware to obtain an initial code; Decompiling the initial code to obtain a target format code; Extracting the operation code from the target format code to obtain the intermediate layer operation code and the native code operation code; Obtaining original application data based on the intermediate layer opcode and the native code opcode; A first obtaining module is used to preprocess the original application data to obtain intermediate application data, wherein the preprocessing includes mapping processing and cleaning processing; Using the TF-ID method to perform data dimension reduction on the intermediate application data, extracting important words in the intermediate application data, and obtaining target training data, wherein the important words have the ability to distinguish categories; forming a training set based on the target training data; A construction module is used to construct an initial prediction model based on a preset bidirectional long-short term recurrent network and a preset text convolutional network; A training module, used to train the initial prediction model using the training set to obtain a target malware prediction model; The second obtaining module is used to obtain the application data to be tested of the Android software to be tested, and process the application data to be tested based on the target malware detection model to obtain the malicious prediction result of the Android software to be tested; wherein, the processing is to use the bidirectional long short-term recurrent network and the text convolutional network of the target malware detection model to process the target data to be tested respectively, and integrate the first result and the second result obtained by the processing by voting method.

7. A computing device comprising a memory, a processor, and a program stored in the memory and running on the processor, characterized in that: When the processor executes the program, the steps of a software detection method for an Android platform as described in any one of claims 1 to 5 are implemented.

8. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores instructions, and when the instructions are executed on a terminal device, the terminal device executes the steps of a software detection method for an Android platform as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • A system and a method for statically detecting malicious software in a container

    CN110008703A

  • Intrusion detection method and device

    CN112437053A

  • Malicious software detection model construction method and device and malicious software detection method and device

    CN115344861A