The invention provides a mobile malicious
software detection method based on heterogeneous flow fusion, realizes more effective capture of malicious behaviors in combination with
semantic information of heterogeneous flows, and belongs to the technical field of
network security. The method comprises the following steps: firstly, explicitly modeling a relationship between entities from different flows by adopting a
heterogeneous information network (HIN), and retaining
semantic relevance of heterogeneous flows; secondly, a meta-path group is constructed for each
stream view, each group comprises content-oriented meta-paths and action-oriented meta-paths, and semantic correlation between applications is established; then, the flow2vec distinguishes HIN entity
semantics of different streams based on context constraints; and finally, fusing semantic embedding of each view through a DNN classifier based on channel attention, and weighting contribution of the semantic embedding to realize accurate detection. According to the method,
semantics of multiple
stream types are integrated, the complementary advantages of the
semantics are expected to be utilized, understanding of application program behaviors is enhanced, and malicious information hidden in application program codes is found.