首页> 外国专利> METHOD AND APPARATUS FOR ANALYZING DYNAMIC BEHAVIOR OF MALICIOUS APPLICATION

METHOD AND APPARATUS FOR ANALYZING DYNAMIC BEHAVIOR OF MALICIOUS APPLICATION

机译:恶意应用程序动态行为分析的方法和装置

摘要

According to an embodiment of the present invention, a method for analyzing a dynamic behavior of a malicious application comprises the steps of: receiving an application suspicious as a malicious application from an application server, and executing the received application in a virtual environment-based emulator; performing a dynamic behavior test for the received application in the executed virtual environment-based emulator; storing a log file generated during the performance of the dynamic behavior test in a database; extracting application program interface (API) information for calling a pre-defined dynamic analysis API when the application is driven, and call count information from the log file; and confirming the API information and the call count information to detect an abnormal behavior for the application. Thus, according to an embodiment of the present embodiment, a malicious behavior of a malicious application is easily detected through a dynamic behavior test based on a virtual environment, and the leakage of personal information is prevented. Also, hard coding is performed with data of an actual terminal through modification of a framework, thereby neutralizing an analysis avoidance attempt through the fingerprinting.;COPYRIGHT KIPO 2017
机译:根据本发明的实施例,一种用于分析恶意应用程序的动态行为的方法包括以下步骤:从应用程序服务器接收可疑为恶意应用程序的应用程序,以及在基于虚拟环境的仿真器中执行接收到的应用程序;在执行的基于虚拟环境的仿真器中为接收到的应用程序执行动态行为测试;将执行动态行为测试期间生成的日志文件存储在数据库中;在应用程序被驱动时,提取用于调用预定义的动态分析API的应用程序接口(API)信息,以及从日志文件中提取调用计数信息;确认API信息和呼叫计数信息,以检测应用程序的异常行为。因此,根据本实施例的实施例,通过基于虚拟环境的动态行为测试容易地检测到恶意应用的恶意行为,并且防止了个人信息的泄露。此外,通过修改框架对实际终端的数据执行硬编码,从而通过指纹抵消了避免分析的尝试。; COPYRIGHT KIPO 2017

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号