作者: Mihai Christodorescu , Vinay Sridhara , Rajarshi Gupta
DOI:
关键词:
摘要: Systems and methods for recognizing reacting to malicious or performance-degrading behaviors in a mobile device include observing an observer module within privileged-normal portion of secure operating environment identify suspicious behavior. The may generate concise behavior vector based on the observations, provide analyzer unprivileged-secure environment. be analyzed determine whether is benign, suspicious, malicious, performance-degrading. If found operations adjusted, such as perform deeper observations. user and/or client alerted secure, tamper-proof manner.