VizMal: A Visualization Tool for Analyzing the Behavior of Android Malware

被引:1
作者
Bacci, Alessandro [1 ]
Martinelli, Fabio [2 ]
Medvet, Eric [1 ]
Mercaldo, Francesco [2 ]
机构
[1] Univ Trieste, Dipartimento Ingn & Architettura, Trieste, Italy
[2] CNR, Ist Informat Telemat, Pisa, Italy
来源
ICISSP: PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY | 2018年
基金
欧盟地平线“2020”;
关键词
Malware Analysis; Android; Machine Learning; Multiple Instance Learning;
D O I
10.5220/0006665005170525
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Malware signature extraction is currently a manual and a time-consuming process. As a matter of fact, security analysts have to manually inspect samples under analysis in order to find the malicious behavior. From research side, current literature is lacking of methods focused on the malicious behavior localization: designed approaches basically mark an entire application as malware or non-malware (i.e., take a binary decision) without knowledge about the malicious behavior localization inside the analysed sample. In this paper, with the twofold aim of assisting the malware analyst in the inspection process and of pushing the research community in malicious behavior localization, we propose VizMal, a tool for visualizing the dynamic trace of an Android application which highlights the portions of the application which look potentially malicious. VizMal performs a detailed analysis of the application activities showing for each second of the execution whether the behavior exhibited is legitimate or malicious. The analyst may hence visualize at a glance when at to which degree an application execution looks malicious.
引用
收藏
页码:517 / 525
页数:9
相关论文
共 36 条
  • [1] Aafer Y, 2013, L N INST COMP SCI SO, V127, P86
  • [2] [Anonymous], 2007, P 24 ANN INT C MACH
  • [3] [Anonymous], 2015, NDSS
  • [4] [Anonymous], 2003, P ADV NEUR INF PROC
  • [5] [Anonymous], 2014, P 21 ANN NETW DISTR
  • [6] Arzt S, 2014, ACM SIGPLAN NOTICES, V49, P259, DOI [10.1145/2594291.2594299, 10.1145/2666356.2594299]
  • [7] Canfora Gerardo, 2015, 2015 Mobile Systems Technologies Workshop (MST). Architecture, Technology Trends and Memory Solutions. Proceedings, P21, DOI 10.1109/MST.2015.8
  • [8] Canfora G., 2014, E INFORM SOFTWARE EN, V8
  • [9] Canfora G., 2015, E BUSINESS TELECOMMU, P201
  • [10] Canfora G., 2015, P 3 INT WORKSH SOFTW, P13