针对移动终端恶意软件泛滥的现状,提出一种诱骗、捕获、分析恶意软件的移动蜜罐(mobilehoneypot,MHP)技术。MHP包含3个核心模块,环境欺骗模块构造出具有诱骗性的安全资源;恶意行为捕获模块通过监听通信端口、扫描系统内存、识别敏感权限来捕获恶意行为;恶意数据分析模块分析捕获数据,识别和定位安全威胁的类型和根源。结果表明:MHP可有效地捕获和识别恶意行为并适于在移动终端部署应用。
Aiming at the increasing attacks to intelligent mobile terminals, MHP (mobile honeypot) is proposed to decoy, capture and analyze malwares. MHP contains'three kernel modules: the decoy module creates fraudulent envi- ronment, the malicious behavior capture module catches malicious behaviors through monitoring communication port, scanning system memory and identifying sensitive permissions and the malicious data analyzing module in- dentifies the types of security threats. Results show that MHP can capture malicious behavior effectively and is suitable for deploying on mobile terminals.