Fingerprinting Android malware families

被引:29
|
作者
Xie, Nannan [1 ,2 ]
Wang, Xing [1 ]
Wang, Wei [1 ]
Liu, Jiqiang [1 ]
机构
[1] Beijing Jiaotong Univ, Beijing Key Lab Secur & Privacy Intelligent Trans, Beijing 100044, Peoples R China
[2] Changchun Univ Sci & Technol, Sch Comp Sci & Technol, Changchun 130022, Jilin, Peoples R China
基金
中国国家自然科学基金;
关键词
Android malware; malware family; feature selection; behavior analysis; AUDIT DATA STREAMS;
D O I
10.1007/s11704-017-6493-y
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The domination of the Android operating system in the market share of smart terminals has engendered increasing threats of malicious applications (apps). Research on Android malware detection has received considerable attention in academia and the industry. In particular, studies on malware families have been beneficial to malware detection and behavior analysis. However, identifying the characteristics of malware families and the features that can describe a particular family have been less frequently discussed in existing work. In this paper, we are motivated to explore the key features that can classify and describe the behaviors of Android malware families to enable fingerprinting the malware families with these features. We present a framework for signature-based key feature construction. In addition, we propose a frequency-based feature elimination algorithm to select the key features. Finally, we construct the fingerprints of ten malware families, including twenty key features in three categories. Results of extensive experiments using Support Vector Machine demonstrate that the malware family classification achieves an accuracy of 92% to 99%. The typical behaviors of malware families are analyzed based on the selected key features. The results demonstrate the feasibility and effectiveness of the presented algorithm and fingerprinting method.
引用
收藏
页码:637 / 646
页数:10
相关论文
共 50 条
  • [31] Challenges in Android Malware Analysis
    Tong, Valerie Viet Triem
    Lalande, Jean Francois
    Leslous, Mourad
    ERCIM NEWS, 2016, (106): : 42 - +
  • [32] Smart malware detection on Android
    Gheorghe, Laura
    Marin, Bogdan
    Gibson, Gary
    Mogosanu, Lucian
    Deaconescu, Razvan
    Voiculescu, Valentin-Gabriel
    Carabas, Mihai
    SECURITY AND COMMUNICATION NETWORKS, 2015, 8 (18) : 4254 - 4272
  • [33] Infrastructure for Detecting Android Malware
    Delosieres, Laurent
    Garcia, David
    INFORMATION SCIENCES AND SYSTEMS 2013, 2013, 264 : 389 - 398
  • [34] TRENDS IN ANDROID MALWARE DETECTION
    Shaerpour, Kaveh
    Dehghantanha, Ali
    Mahmod, Ramlan
    JOURNAL OF DIGITAL FORENSICS SECURITY AND LAW, 2013, 8 (03) : 21 - 40
  • [35] Orchestrating Android Malware Experiments
    Lalande, Jean-Francois
    Graux, Pierre
    Miranda, Tomas Concepcion
    2019 IEEE 27TH INTERNATIONAL SYMPOSIUM ON MODELING, ANALYSIS, AND SIMULATION OF COMPUTER AND TELECOMMUNICATION SYSTEMS (MASCOTS 2019), 2019, : 433 - 434
  • [36] The analysis of android malware behaviors
    Department of Computer and Information Engineering, Huainan Normal University, Huainan, China
    Int. J. Secur. Appl., 3 (335-346):
  • [37] Framework for malware analysis in Android
    Urcuqui Lopez, Christian Camilo
    Navarro Cadavid, Andres
    SISTEMAS & TELEMATICA, 2016, 14 (37): : 45 - 56
  • [38] The Analysis of Android Malware Behaviors
    Fan Yuhui
    Xu Ning
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2015, 9 (03): : 335 - 345
  • [39] Features to Detect Android Malware
    Urcuqui Lopez, Christian Camilo
    Delgado Villarreal, Jhoan Steven
    Perez Belalcazar, Andres Felipe
    Navarro Cadavid, Andres
    Diaz Cely, Javier Gustavo
    2018 IEEE COLOMBIAN CONFERENCE ON COMMUNICATIONS AND COMPUTING (COLCOM), 2018,
  • [40] Identifying Android Malware Instructions
    Morales Medina, Laura Victoria
    Rueda, Sandra Julieta
    2014 IEEE LATIN-AMERICA CONFERENCE ON COMMUNICATIONS (LATINCOM), 2014,