Detection of Android Malicious Apps Based on the Sensitive Behaviors

被引:12
|
作者
Quan, Daiyong [1 ]
Zhai, Lidong [1 ]
Yang, Fan [1 ]
Wang, Peng [1 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
来源
2014 IEEE 13TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM) | 2014年
关键词
Android; Sensitive behavior feature vector; Malware detection;
D O I
10.1109/TrustCom.2014.115
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The number of malicious applications (apps) targeting the Android system has exploded in recent years. The evolution of malware makes it difficult to detect for static analysis tools. Various behavior-based malware detection techniques to mitigate this problem have been proposed. The drawbacks of the existing approaches are: the behavior features extracted from a single source lead to the low detection accuracy and the detection process is too complex. Especially it is unsuitable for smart phones with limited computing power. In this paper, we extract sensitive behavior features from three sources: API calls, native code dynamic execution, and system calls. We propose a sensitive behavior feature vector for representation multi-source behavior features uniformly. Our sensitive behavior representation is able to automatically describe the low-level OS-specific behaviors and high-level application-specific behaviors of an Android malware. Based on the unified behavior feature representation, we provide a light weight decision function to differentiate a given application benign or malicious. We tested the effectiveness of our approach against real malware and the results of our experiments show that its detection accuracy up to 96% with acceptable performance overhead. For a given threshold t (t=9), we can detect the advanced malware family effectively.
引用
收藏
页码:877 / 883
页数:7
相关论文
共 50 条
  • [1] Network-based detection of Android malicious apps
    Shree Garg
    Sateesh K. Peddoju
    Anil K. Sarje
    International Journal of Information Security, 2017, 16 : 385 - 400
  • [2] Network-based detection of Android malicious apps
    Garg, Shree
    Peddoju, Sateesh K.
    Sarje, Anil K.
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2017, 16 (04) : 385 - 400
  • [3] A Survey on the Detection of Android Malicious Apps
    Sahay, Sanjay K.
    Sharma, Ashu
    ADVANCES IN COMPUTER COMMUNICATION AND COMPUTATIONAL SCIENCES, IC4S 2018, 2019, 924 : 437 - 446
  • [4] MOWAD: Automation-based Detection of Malicious OfferWall Android Apps
    Zhang, Shaodong
    Feng, Dong
    Li, Qi
    PROCEEDINGS OF 2017 2ND INTERNATIONAL CONFERENCE ON COMMUNICATION AND INFORMATION SYSTEMS (ICCIS 2017), 2015, : 239 - 243
  • [5] A MACHINE LEARNING APPROACH TO THE DETECTION AND ANALYSIS OF ANDROID MALICIOUS APPS
    Shibija, K.
    Raymond, Joseph, V
    2018 INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATION AND INFORMATICS (ICCCI), 2018,
  • [6] Extracting Android Malicious Behaviors
    Khanh-Huu-The Dam
    Touili, Tayssir
    ICISSP: PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2017, : 714 - 723
  • [7] On Locating Malicious Code in Piggybacked Android Apps
    Li, Li
    Li, Daoyuan
    Bissyande, Tegawende F.
    Klein, Jacques
    Cai, Haipeng
    Lo, David
    Le Traon, Yves
    JOURNAL OF COMPUTER SCIENCE AND TECHNOLOGY, 2017, 32 (06) : 1108 - 1124
  • [8] An Investigation of the Classifiers to Detect Android Malicious Apps
    Sharma, Ashu
    Sahay, Sanjay Kumar
    INFORMATION AND COMMUNICATION TECHNOLOGY (ICICT 2016), 2018, 625 : 207 - 217
  • [9] On Locating Malicious Code in Piggybacked Android Apps
    Li Li
    Daoyuan Li
    Tegawendé F. Bissyandé
    Jacques Klein
    Haipeng Cai
    David Lo
    Yves Le Traon
    Journal of Computer Science and Technology, 2017, 32 : 1108 - 1124
  • [10] Enhancing Malware Detection for Android Apps: Detecting Fine-granularity Malicious Components
    Liu, Zhijie
    Zhang, Liang Feng
    Tang, Yutian
    2023 38TH IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING, ASE, 2023, : 1212 - 1224