首页> 外文会议>Applied cryptography and network security >A Specification Based Intrusion Detection Framework for Mobile Phones
【24h】

A Specification Based Intrusion Detection Framework for Mobile Phones

机译:基于规范的手机入侵检测框架

获取原文
获取原文并翻译 | 示例

摘要

With the fast growth of mobile market, we are now seeing more and more malware on mobile phones. One common pattern of many commonly found malware on mobile phones is that: the malware always attempts to access sensitive system services on the mobile phone in an unobtrusive and stealthy fashion. For example, the malware may send messages automatically or stealthily interface with the audio peripherals on the device without the user's awareness and authorization. To detect the unauthorized malicious behavior, we present SBIDF, a Specification Based Intrusion Detection Framework, which utilizes the keypad or touchscreen interrupts to differentiate between malware and human activity. Specifically, in the proposed framework, we use an application independent specification, written in Temporal Logic of Causal Knowledge (TLCK), to describe the normal behavior pattern, and enforce this specification to all third party applications on the mobile phone during runtime by monitoring the inter-component communication pattern among critical components. Our evaluation of simulated behavior of real world malware shows that we are able to detect all forms of malware that attempts to access sensitive services without possessing user's permission. Furthermore, the SBIDF incurs a negligible overhead (20 μ sees) which makes it very feasible for real world deployment.
机译:随着移动市场的快速增长,我们现在看到越来越多的手机恶意软件。许多常见的在手机上发现的恶意软件的一种常见模式是:恶意软件总是试图以不显眼和隐秘的方式访问手机上的敏感系统服务。例如,恶意软件可能会自动发送消息或与设备上的音频外围设备秘密地进行交互,而无需用户的意识和授权。为了检测未经授权的恶意行为,我们提出了SBIDF,这是一个基于规范的入侵检测框架,该框架利用键盘或触摸屏中断来区分恶意软件和人类活动。具体来说,在提出的框架中,我们使用因果知识的时态逻辑(TLCK)编写的与应用程序无关的规范来描述正常的行为模式,并通过监控运行时在手机上的所有第三方应用程序对该规范的实施。关键组件之间的组件间通信模式。我们对现实世界中恶意软件模拟行为的评估表明,我们能够检测到所有形式的恶意软件,这些恶意软件试图在未经用户许可的情况下访问敏感服务。此外,SBIDF产生的开销可忽略不计(见20μs),这使其在现实世界中的部署非常可行。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号