首页 | 官方网站   微博 | 高级检索  
     

基于域名关联的恶意移动应用检测研究
引用本文:蔡荣彦,王鹤,姚启桂,何高峰.基于域名关联的恶意移动应用检测研究[J].计算机工程,2020,46(5):174-180.
作者姓名:蔡荣彦  王鹤  姚启桂  何高峰
作者单位:国网福建省电力有限公司,福州350003;全球能源互联网研究院有限公司,南京210003;南京邮电大学物联网学院,南京210023;东南大学计算机网络和信息集成教育部重点实验室,南京211189
摘    要:为实现对恶意移动应用的准确检测以保障移动设备安全,提出一种基于域名关联的恶意移动应用检测方法。以DNS域名为检测分析对象识别网络流量中的恶意域名,利用DNS请求流量的时间特征寻找恶意域名的相关联域名,并将关联域名与文本分类样本库进行比对,确定恶意移动应用名称。实验结果表明,该方法可有效用于移动设备的安全防护,其在公开测试数据集中的检测率达到97.1%,在实际网络的部署运行中共检测出13款恶意移动应用,且误报数量为0。

关 键 词:恶意域名  时间特征  域名关联  文本检索  分类

Research on Malicious Mobile Application Detection Based on Domain Name Association
CAI Rongyan,WANG He,YAO Qigui,HE Gaofeng.Research on Malicious Mobile Application Detection Based on Domain Name Association[J].Computer Engineering,2020,46(5):174-180.
Authors:CAI Rongyan  WANG He  YAO Qigui  HE Gaofeng
Affiliation:(State Grid Fujian Electric Power Co.,Ltd.,Fuzhou 350003,China;Global Energy Internet Research Institute Co.,Ltd.,Nanjing 210003,China;College of Internet of Things,Nanjing University of Posts and Telecommunications,Nanjing 210023,China;Key Laboratory of Computer Network and Information Integration of Ministry of Education,Southeast University,Nanjing 211189,China)
Abstract:In order to realize the accurate detection of malicious mobile applications and ensure the security of mobile devices,a malicious mobile application detection method based on DNS is proposed.DNS domain name is used as the analysis object of detection to identify the malicious domain name in the network traffic,the time characteristics of DNS request traffic are used to find the associated domain name of the malicious domain name,and the associated domain name is compared with the text classification sample library to determine the name of the malicious mobile application.The experimental results show that this method can be effectively applied to the security protection of mobile devices.The detection rate of this method in the public test data set is 97.1%,and a total of thirteen malicious mobile applications are detected in the actual network deployment,and the number of false positives is 0.
Keywords:malicious domain name  time characteristic  domain name association  text retrieval  classification
本文献已被 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号