Evolution, Detection and Analysis of Malware for Smart Devices

被引:141
作者
Suarez-Tangil, Guillermo [1 ]
Tapiador, Juan E. [1 ]
Peris-Lopez, Pedro [1 ]
Ribagorda, Arturo [1 ]
机构
[1] Univ Carlos III Madrid, Dept Comp Sci, Comp Secur Lab COSEC, Madrid 28911, Spain
关键词
smart devices; malware; grayware; smartphones; security; privacy; SECURITY; ATTACKS; SYSTEMS; COMPUTER; NETWORKS; FUTURE;
D O I
10.1109/SURV.2013.101613.00077
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Smart devices equipped with powerful sensing, computing and networking capabilities have proliferated lately, ranging from popular smartphones and tablets to Internet appliances, smart TVs, and others that will soon appear (e.g., watches, glasses, and clothes). One key feature of such devices is their ability to incorporate third-party apps from a variety of markets. This poses strong security and privacy issues to users and infrastructure operators, particularly through software of malicious (or dubious) nature that can easily get access to the services provided by the device and collect sensory data and personal information. Malware in current smart devices -mostly smartphones and tablets- have rocketed in the last few years, in some cases supported by sophisticated techniques purposely designed to overcome security architectures currently in use by such devices. Even though important advances have been made on malware detection in traditional personal computers during the last decades, adopting and adapting those techniques to smart devices is a challenging problem. For example, power consumption is one major constraint that makes unaffordable to run traditional detection engines on the device, while externalized (i.e., cloud-based) techniques rise many privacy concerns. This article examines the problem of malware in smart devices and recent progress made in detection techniques. We first present a detailed analysis on how malware has evolved over the last years for the most popular platforms. We identify exhibited behaviors, pursued goals, infection and distribution strategies, etc. and provide numerous examples through case studies of the most relevant specimens. We next survey, classify and discuss efforts made on detecting both malware and other suspicious software (grayware), concentrating on the 20 most relevant techniques proposed between 2010 and 2013. Based on the conclusions extracted from this study, we finally provide constructive discussion on open research problems and areas where we believe that more work is needed.
引用
收藏
页码:961 / 987
页数:27
相关论文
共 50 条
[41]   Guest Editorial Special Section on Security, Privacy and Trust for Consumer Smart Devices [J].
Meng, Weizhi ;
Lu, Rongxing ;
Zhang, Jun ;
Samarati, Pierangela .
IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2024, 70 (01) :3960-3962
[42]   Formal Equivalence Checking for Mobile Malware Detection and Family Classification [J].
Mercaldo, Francesco ;
Santone, Antonella .
IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2021, 48 (07) :2643-2657
[43]   On the feasibility of adversarial machine learning in malware and network intrusion detection [J].
Venturi, Andrea ;
Zanasi, Claudio .
2021 IEEE 20TH INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS (NCA), 2021,
[44]   A Context-Aware Framework for Detecting Sensor-Based Threats on Smart Devices [J].
Sikder, Amit Kumar ;
Aksu, Hidayet ;
Uluagac, A. Selcuk .
IEEE TRANSACTIONS ON MOBILE COMPUTING, 2020, 19 (02) :245-261
[45]   Optimization of Lightweight Malware Detection Models For AIoT Devices [J].
Lo, Felicia ;
Kaliski, Rafael ;
Cheng, Shin-Ming .
2023 IEEE 9TH WORLD FORUM ON INTERNET OF THINGS, WF-IOT, 2023,
[46]   The Evolution of Permission as Feature for Android Malware Detection [J].
Gaviria de la Puerta, Jose ;
Sanz, Borja ;
Santos Grueiro, Igor ;
Garcia Bringas, Pablo .
INTERNATIONAL JOINT CONFERENCE: CISIS'15 AND ICEUTE'15, 2015, 369 :389-400
[47]   Efficient signature based malware detection on mobile devices [J].
Venugopal, Deepak ;
Hu, Guoning .
MOBILE INFORMATION SYSTEMS, 2008, 4 (01) :33-49
[48]   Impact of Code Obfuscation on Android Malware Detection based on Static and Dynamic Analysis [J].
Bacci, Alessandro ;
Bartoli, Alberto ;
Martinelli, Fabio ;
Medvet, Eric ;
Mercaldo, Francesco ;
Visaggio, Corrado Aaron .
ICISSP: PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2018, :379-385
[49]   A Multimodal Malware Detection Technique for Android IoT Devices Using Various Features [J].
Kumar, Rajesh ;
Zhang, Xiaosong ;
Wang, Wenyong ;
Khan, Riaz Ullah ;
Kumar, Jay ;
Sharif, Abubaker .
IEEE ACCESS, 2019, 7 :64411-64430
[50]   Artificial Intelligence Algorithms for Malware Detection in Android-Operated Mobile Devices [J].
Alkahtani, Hasan ;
Aldhyani, Theyazn H. H. .
SENSORS, 2022, 22 (06)