Uncovering the Face of Android Ransomware: Characterization and Real-Time Detection

被引:105
|
作者
Chen, Jing [1 ,2 ]
Wang, Chiheng [1 ]
Zhao, Ziming [3 ]
Chen, Kai [4 ,5 ]
Du, Ruiying [6 ]
Ahn, Gail-Joon [7 ,8 ]
机构
[1] Wuhan Univ, Comp Sch, Key Lab Aerosp Informat Secur & Trusted Comp, Minist Educ, Wuhan 430072, Hubei, Peoples R China
[2] Sci & Technol Commun Secur Lab, Chengdu 610041, Sichuan, Peoples R China
[3] Arizona State Univ, Sch Comp Informat & Decis Syst Engn, Tempe, AZ 85287 USA
[4] Chinese Acad Sci, Inst Informat Engn, SKLOIS, Beijing 100049, Peoples R China
[5] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing 100190, Peoples R China
[6] Collaborat Innovat Ctr Geospatial Technol, Wuhan 430079, Peoples R China
[7] Arizona State Univ, Tempe, AZ 85287 USA
[8] Samsung Res, Seoul, South Korea
基金
中国国家自然科学基金;
关键词
Ransomware; Android; real-time detection; user interface (UI) indicator;
D O I
10.1109/TIFS.2017.2787905
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In recent years, we witnessed a drastic increase of ransomware, especially on popular mobile platforms including Android. Ransomware extorts victims for a sum of money by taking control of their devices or files. In light of their rapid growth, there is a pressing need to develop effective countermeasure solutions. However, the research community is still constrained by the lack of a comprehensive data set, and there exists no insightful understanding of mobile ransomware in the wild. In this paper, we focus on the Android platform and aim to characterize existing Android ransomware. Specifically, we have managed to collect 2,721 ransomware samples that cover the majority of existing Android ransomware families. Based on these samples, we systematically characterize them from several aspects, including timeline and malicious features. In addition, the detection results of existing anti-virus tools are rather disappointing, which clearly calls for customized anti-mobile-ransomware solutions. To detect ransomware that extorts users by encrypting data, we propose a novel real-time detection system, called RansomProber. By analyzing the user interface widgets of related activities and the coordinates of users' finger movements, RansomProber can infer whether the file encryption operations are initiated by users. The experimental results show that RansomProber can effectively detect encrypting ransomware with high accuracy and acceptable runtime performance.
引用
收藏
页码:1286 / 1300
页数:15
相关论文
共 50 条
  • [1] Real Time Android Ransomware Detection by Analyzed Android Applications
    Ko, Ju-Seong
    Jo, Jeong-Seok
    Kim, Deuk-Hun
    Choi, Seul-Ki
    Kwak, Jin
    2019 INTERNATIONAL CONFERENCE ON ELECTRONICS, INFORMATION, AND COMMUNICATION (ICEIC), 2019, : 375 - 379
  • [2] DNA-Droid: A Real-Time Android Ransomware Detection Framework
    Gharib, Amirhossein
    Ghorbani, Ali
    NETWORK AND SYSTEM SECURITY, 2017, 10394 : 184 - 198
  • [3] RWGuard: A Real-Time Detection System Against Cryptographic Ransomware
    Mehnaz, Shagufta
    Mudgerikar, Anand
    Bertino, Elisa
    RESEARCH IN ATTACKS, INTRUSIONS, AND DEFENSES, RAID 2018, 2018, 11050 : 114 - 136
  • [4] Extinguishing Ransomware - A Hybrid Approach to Android Ransomware Detection
    Ferrante, Alberto
    Malek, Miroslaw
    Martinelli, Fabio
    Mercaldo, Francesco
    Milosevic, Jelena
    FOUNDATIONS AND PRACTICE OF SECURITY (FPS 2017), 2018, 10723 : 242 - 258
  • [5] Real-time system call-based ransomware detection
    Chew, Christopher Jun Wen
    Kumar, Vimal
    Patros, Panos
    Malik, Robi
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2024, 23 (03) : 1839 - 1858
  • [6] Real-time Motion Detection for Android Smartphones
    Andrade, Cassiano
    Silva, Ismael
    Barbosa, Glivia
    Coutinho, Flavio
    2019 18TH BRAZILIAN SYMPOSIUM ON COMPUTER GAMES AND DIGITAL ENTERTAINMENT (SBGAMES 2019), 2019, : 154 - 162
  • [7] Ransomware Detection System for Android Applications
    Alsoghyer, Samah
    Almomani, Iman
    ELECTRONICS, 2019, 8 (08)
  • [8] Real-time Detection of Malicious Behavior in Android Apps
    Ni, Zhenyu
    Yang, Ming
    Ling, Zhen
    Wu, Jia-nan
    Luo, Junzhou
    2016 FOURTH INTERNATIONAL CONFERENCE ON ADVANCED CLOUD AND BIG DATA (CBD 2016), 2016, : 221 - 227
  • [9] Real-Time Android with RTDroid
    Yan, Yin
    Cosgrove, Shaun
    Anand, Varun
    Kulkarni, Amit
    Konduri, Sree Harsha
    Ko, Steven Y.
    Ziarek, Lukasz
    MOBISYS'14: PROCEEDINGS OF THE 12TH ANNUAL INTERNATIONAL CONFERENCE ON MOBILE SYSTEMS, APPLICATIONS, AND SERVICES, 2014, : 273 - 286
  • [10] Real-time Detection of Passive Backdoor Behaviors on Android System
    Yao, Yao
    Zhu, Lipeng
    Wang, He
    2018 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2018,