StormDroid: A Streaminglized Machine Learning-Based System for Detecting Android Malware

被引:109
作者
Chen, Sen [1 ]
Xue, Minhui [2 ]
Tang, Zhushou [3 ,4 ]
Xu, Lihua [1 ]
Zhu, Haojin [5 ]
机构
[1] East China Normal Univ, Dept Comp Sci, Shanghai, Peoples R China
[2] East China Normal Univ, NYU Shanghai, Shanghai, Peoples R China
[3] Shanghai Jiao Tong Univ, Pwnzen Infotech Inc, Shanghai 200030, Peoples R China
[4] Pwnzen Infotech Inc, Shanghai, Peoples R China
[5] Shanghai Jiao Tong Univ, Dept Comp Sci, Shanghai 200030, Peoples R China
来源
ASIA CCS'16: PROCEEDINGS OF THE 11TH ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY | 2016年
关键词
Malware Detection; Machine Learning; StormDroid;
D O I
10.1145/2897845.2897860
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Mobile devices are especially vulnerable nowadays to malware attacks, thanks to the current trend of increased app downloads. Despite the significant security and privacy concerns it received, effective malware detection (MD) remains a significant challenge. This paper tackles this challenge by introducing a streaminglized machine learning-based MD framework, StormDroid: (i) The core of StormDroid is based on machine learning, enhanced with a novel combination of contributed features that we observed over a fairly large collection of data set; and (ii) we streaminglize the whole MD process to support large-scale analysis, yielding an efficient and scalable MD technique that observes app behaviors statically and dynamically. Evaluated on roughly 8,000 applications, our combination of contributed features improves MD accuracy by almost 10% compared with state-of-the-art antivirus systems; in parallel our streaminglized process, StormDroid, further improves efficiency rate by approximately three times than a single thread.
引用
收藏
页码:377 / 388
页数:12
相关论文
共 42 条
[1]  
Aafer Y, 2013, L N INST COMP SCI SO, V127, P86
[2]  
Allix K., 2014, P 4 ACM C DAT APPL S, P163
[3]  
[Anonymous], P NETW DISTR SYST SE
[4]  
[Anonymous], 2015, USENIX SECURITY
[5]  
[Anonymous], 2014 NETW DISTR SYST
[6]  
[Anonymous], 2012, P 10 INT C MOB SYST
[7]  
[Anonymous], 2010, Proceedings of the 5th ACM Symposium on Information, Computer and Communications Security, ASIACCS '10, DOI [10.1145/1755688.1755732, DOI 10.1145/1755688.1755732]
[8]  
[Anonymous], 2012, Proceedings of the 19th ACM Conference on Computer and Communications Security, DOI DOI 10.1145/2382196.2382223
[9]  
[Anonymous], THE JOURNAL OF MACHI
[10]  
[Anonymous], 2013, Proceedings of ACM Conference on Data and Application Security and Privacy (CODASPY)