2015 · 137 citations · 23 references
Smart DevicesMobile SecurityEngineeringMachine LearningEvasion TechniqueInformation SecurityInformation ForensicsUnknown MalwareSoftware AnalysisHardware SecurityData ScienceData MiningPattern RecognitionAndroid MalwareMobile MalwareMobile ComputingComputer ScienceProgram AnalysisAnti-virus TechniqueMalware Analysis
Android malware is proliferating as smart devices and a dynamic app ecosystem expand, yet current detection methods—static or dynamic—suffer from low accuracy, evasion susceptibility, and limited validation. This work proposes a malware detection approach that uses sequences of system calls to overcome these shortcomings. The approach learns fingerprints of malicious behaviors from system call sequences via machine learning and applies them to detect malware, including previously unseen variants. Evaluation on 20,000 execution traces from 2,000 apps, including 1,000 malware samples, achieved 97 % accuracy and demonstrated the method’s ability to detect unknown malware.
The increasing diffusion of smart devices, along with the dynamism of the mobile applications ecosystem, are boosting the production of malware for the Android platform. So far, many different methods have been developed for detecting Android malware, based on either static or dynamic analysis. The main limitations of existing methods include: low accuracy, proneness to evasion techniques, and weak validation, often limited to emulators or modified kernels. We propose an Android malware detection method, based on sequences of system calls, that overcomes these limitations. The assumption is that malicious behaviors (e.g., sending high premium rate SMS, cyphering data for ransom, botnet capabilities, and so on) are implemented by specific system calls sequences: yet, no apriori knowledge is available about which sequences are associated with which malicious behaviors, in particular in the mobile applications ecosystem where new malware and non-malware applications continuously arise. Hence, we use Machine Learning to automatically learn these associations (a sort of "fingerprint" of the malware); then we exploit them to actually detect malware. Experimentation on 20000 execution traces of 2000 applications (1000 of them being malware belonging to different malware families), performed on a real device, shows promising results: we obtain a detection accuracy of 97%. Moreover, we show that the proposed method can cope with the dynamism of the mobile apps ecosystem, since it can detect unknown malware.
23
Drebin: Effective and Explainable Detection of Android Malware in Your Pocket
Daniel J. Arp, Michael Spreitzenbarth, Hugo Gascón et al. · 2014 · 2.2K citations
Dissecting Android Malware: Characterization and Evolution
Yajin Zhou, Xuxian Jiang · 2012 · 2.1K citations
Android permissions demystified
Adrienne Porter Felt, Erika Chin, Steve Hanna et al. · 2011 · 1.3K citations
DroidMat: Android Malware Detection through Manifest and API Calls Tracing
Dong-Jie Wu, Ching-Hao Mao, Te-En Wei et al. · 2012 · 625 citations