随着Android移动终端的普及,Android操作系统已经成为了越来越多的恶意软件攻击的目标。然而不同恶意软件的威胁程度是不同的,例如窃取用户银行账户的应用的威胁性要远大于读取用户联系人的应用的威胁性。因此本文针对这个问题提出了Android手机应用安全等级评估的模型,可以为用户使用的Android手机应用提供不同安全评级。模型首先基于正负相关的卡方检验算法得到安全属性安全值,重点利用多重对应分析方法得到安全属性组合安全值,最后根据前面获得的安全值评定Android手机应用安全等级。通过关联规则实验对安全等级评估模型进行验证,对安全属性安全值和安全属性组合安全值进行分析,实验结果表明该模型是准确有效的。
With the popularity of android smart-phone, the android OS has being become the target of more and more malwares. However, different malwares have different threat. For example, stealing users' bank account information poses a greater threat than the application to load users' contacts. So this paper provides an assessment model of android application security level, providing different security levels for different android applications. Firstly, our model obtains the security value of security attribute by the Chi-square test based on positive and negative correlation and then uses multiple correspondence analysis method to get security value of security attribute combination. Finally, we assess the security level of android applications according to the security values before. We validate the security level of the assessment model with the association rules, analyze the security value of security attribute and the security value of security attribute combination, the experimental results show that our model is accurate and effective.