Countering Android Malware: A Scalable Semi-Supervised Approach for Family-Signature Generation

被引:18
作者
Atzeni, Andrea [1 ]
Diaz, Fernando [2 ]
Marcelli, Andrea [1 ]
Sanchez, Antonio [2 ]
Squillero, Giovanni [1 ]
Tonda, Alberto [3 ]
机构
[1] Politecn Torino, Dept Control & Comp Engn DAWN, I-10129 Turin, Italy
[2] Hispasec Sistemas SL, Malaga 29001, Spain
[3] INRA, UMR GMPA 782, F-78850 Thiverval Grignon, France
关键词
Semi-supervised learning; clustering; android; malware; automatic signature generation; CLASSIFICATION; BEHAVIOR;
D O I
10.1109/ACCESS.2018.2874502
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Reducing the effort required by humans in countering malware is of utmost practical value. We describe a scalable, semi-supervised framework to dig into massive data sets of Android applications and identify new malware families. Until 2010, the industrial standard for the detection of malicious applications has been mainly based on signatures; as each tiny alteration in malware makes them ineffective, new signatures are frequently created - a task that requires a considerable amount of time and resources from skilled experts. The framework we propose is able to automatically cluster applications in families and suggest formal rules for identifying them with 100% recall and quite high precision. The families are used either to safely extend experts' knowledge on new samples or to reduce the number of applications requiring thorough analyses. We demonstrated the effectiveness and the scalability of the approach running experiments on a database of 1.5 million Android applications. In 2018, the framework has been successfully deployed on Koodous, a collaborative anti-malware platform.
引用
收藏
页码:59540 / 59556
页数:17
相关论文
共 62 条
[1]  
[Anonymous], 2004, P 6 C S OP SYST DES
[2]  
[Anonymous], P 2007 JOINT C EMP M
[3]  
[Anonymous], 2008, VIRUS B RULE DRIVEN
[4]  
[Anonymous], 2004, P 13 C USENIX SEC S
[5]  
[Anonymous], 2015, P 8 WORKSH CYB SEC E
[6]  
[Anonymous], 2013, 2013 USENIX ANN TECH
[7]  
[Anonymous], 2013, YARA THE PATTERN MAT
[8]  
[Anonymous], 2013, Proceedings of the 6th international conference on security of information and networks, DOI DOI 10.1145/2523514.2523539
[9]  
[Anonymous], 2011, Tech. Rep
[10]  
[Anonymous], 2016, MALICIALAB AVCLASS A