Fingerprinting Android malware families

被引:29
|
作者
Xie, Nannan [1 ,2 ]
Wang, Xing [1 ]
Wang, Wei [1 ]
Liu, Jiqiang [1 ]
机构
[1] Beijing Jiaotong Univ, Beijing Key Lab Secur & Privacy Intelligent Trans, Beijing 100044, Peoples R China
[2] Changchun Univ Sci & Technol, Sch Comp Sci & Technol, Changchun 130022, Jilin, Peoples R China
基金
中国国家自然科学基金;
关键词
Android malware; malware family; feature selection; behavior analysis; AUDIT DATA STREAMS;
D O I
10.1007/s11704-017-6493-y
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The domination of the Android operating system in the market share of smart terminals has engendered increasing threats of malicious applications (apps). Research on Android malware detection has received considerable attention in academia and the industry. In particular, studies on malware families have been beneficial to malware detection and behavior analysis. However, identifying the characteristics of malware families and the features that can describe a particular family have been less frequently discussed in existing work. In this paper, we are motivated to explore the key features that can classify and describe the behaviors of Android malware families to enable fingerprinting the malware families with these features. We present a framework for signature-based key feature construction. In addition, we propose a frequency-based feature elimination algorithm to select the key features. Finally, we construct the fingerprints of ten malware families, including twenty key features in three categories. Results of extensive experiments using Support Vector Machine demonstrate that the malware family classification achieves an accuracy of 92% to 99%. The typical behaviors of malware families are analyzed based on the selected key features. The results demonstrate the feasibility and effectiveness of the presented algorithm and fingerprinting method.
引用
收藏
页码:637 / 646
页数:10
相关论文
共 50 条
  • [1] Fingerprinting Android malware families
    Nannan Xie
    Xing Wang
    Wei Wang
    Jiqiang Liu
    Frontiers of Computer Science, 2019, 13 : 637 - 646
  • [2] Neural Visualization of Android Malware Families
    Gonzalez, Alejandro
    Herrero, Alvaro
    Corchado, Emilio
    INTERNATIONAL JOINT CONFERENCE SOCO'16- CISIS'16-ICEUTE'16, 2017, 527 : 574 - 583
  • [3] Fingerprinting Android packaging: Generating DNAs for malware detection
    Karbab, ElMouatez Billah
    Debbabi, Mourad
    Mouheb, Djedjiga
    DIGITAL INVESTIGATION, 2016, 18 : S33 - S45
  • [4] DySign: Dynamic Fingerprinting for the Automatic Detection of Android Malware
    Karbab, ElMouatez Billah
    Debbabi, Mourad
    Alrabaee, Saed
    Mouheb, Djedjiga
    2016 11TH INTERNATIONAL CONFERENCE ON MALICIOUS AND UNWANTED SOFTWARE (MALWARE), 2016, : 139 - 146
  • [5] Clustering Android Malware Families by Http Traffic
    Aresu, Marco
    Ariu, Davide
    Ahmadi, Mansour
    Maiorca, Davide
    Giacinto, Giorgio
    2015 10TH INTERNATIONAL CONFERENCE ON MALICIOUS AND UNWANTED SOFTWARE (MALWARE), 2015, : 128 - 135
  • [6] Key features for the characterization of Android malware families
    Sedano, Javier
    Gonzalez, Silvia
    Chira, Camelia
    Herrero, Alvaro
    Corchado, Emilio
    Ramon Villar, Jose
    LOGIC JOURNAL OF THE IGPL, 2017, 25 (01) : 54 - 66
  • [7] Using AI to Detect Android Malware Families
    Alrabaee, Saed
    Al-kfairy, Mousa
    Taha, Mohammad Bany
    Alfandi, Omar
    Taher, Fatma
    El Fiky, Ahmed Hashem
    20TH INTERNATIONAL CONFERENCE ON THE DESIGN OF RELIABLE COMMUNICATION NETWORKS, DRCN 2024, 2024,
  • [8] Identifying Android Malware Families Using Android-Oriented Metrics
    Blanc, William
    Hashem, Lina G.
    Elish, Karim O.
    Almohri, Hussain M. J.
    2019 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2019, : 4708 - 4713
  • [9] Characterization of Android Malware Families by a Reduced Set of Static Features
    Sedano, Javier
    Chira, Camelia
    Gonzalez, Silvia
    Herrero, Alvaro
    Corchado, Emilio
    Ramon Villars, Jose
    INTERNATIONAL JOINT CONFERENCE SOCO'16- CISIS'16-ICEUTE'16, 2017, 527 : 607 - 617
  • [10] Advanced 3D Visualization of Android Malware Families
    Basurto, Nuno
    Quintian, Hector
    Urda, Daniel
    Calvo-Rolle, Jose Luis
    Herrero, Alvaro
    Corchado, Emilio
    14TH INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE IN SECURITY FOR INFORMATION SYSTEMS AND 12TH INTERNATIONAL CONFERENCE ON EUROPEAN TRANSNATIONAL EDUCATIONAL (CISIS 2021 AND ICEUTE 2021), 2022, 1400 : 167 - 177