Detection of Android Malicious Obfuscation Applications Based on Multi-class Features

被引:0
|
作者
Zhao, Meichen [1 ]
机构
[1] Beijing Jiaotong Univ, Beijing Key Lab Secur & Privacy Intelligent Trans, Beijing, Peoples R China
基金
国家重点研发计划;
关键词
Android applications; obfuscation detection; malapp detection; static analysis;
D O I
10.1109/IMCCC.2018.00370
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In recent years, obfuscation technology is more and more widely utilized by Android applications (apps). Legitimate app developers employ this technology to protect their intellectual property. However, malicious app (malapp) authors obfuscate their apps to increase the difficulty of reverse-analysis-engineer and to evade signature-based detection. Static analysis method is the main approach to detect malapps. Unfortunately, many static analysis techniques are easily thwarted by obfuscation technology. How to detect obfuscated malapps effectively is thus a big challenge. In this work, we construct a model that detects obfuscated malapps, including obfuscation detection and malapp detection. The module of obfuscation detection extracts the identifier names of classes and methods of apps as features, employing n-gram to generate a fixed-length feature vector for each app. Then it applies Support Vector Machine (SVM) for classifying apps into obfuscation or non-obfuscation. In term of the module of malapp detection, we firstly extract many kinds of features from the APK (Android package) file with static analysis technology, such as Permission, Intent and so on. Then we use SVM to evaluate the performance of this module. Extensive experimental results demonstrate the effectiveness of our methods. The accuracy of obfuscation detection reaches 90.91%, and the F-score arrives at 0.91. Besides, our malapp detection module can exactly detect 97.32% apps.
引用
收藏
页码:1795 / 1799
页数:5
相关论文
共 50 条
  • [1] A malware behavior detection system of android applications based on multi-class features
    Yang, H. (yangh@nipc.org.cn), 1600, Science Press (37):
  • [2] Binary and multi-class classification of Android applications using static features
    Dhalaria, Meghna
    Gandotra, Ekta
    INTERNATIONAL JOURNAL OF APPLIED MANAGEMENT SCIENCE, 2023, 15 (02) : 117 - 140
  • [3] BEHAVIOR-BASED MALICIOUS EXECUTABLES DETECTION BY MULTI-CLASS SVM
    Zou, Meng-song
    Han, Lan-sheng
    Liu, Qi-wen
    Liu, Ming
    2009 IEEE YOUTH CONFERENCE ON INFORMATION, COMPUTING AND TELECOMMUNICATION, PROCEEDINGS, 2009, : 331 - 334
  • [4] Malicious Android Application Detection Based on Composite Features
    Xiao, Jingxu
    Xu, Kaiyong
    Duan, Jialiang
    PROCEEDINGS OF THE THIRD INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND APPLICATION ENGINEERING (CSAE2019), 2019,
  • [5] Detection of Obfuscation Techniques in Android Applications
    Bacci, Alessandro
    Bartoli, Alberto
    Martinelli, Fabio
    Medvet, Eric
    Mercaldo, Francesco
    13TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2018), 2019,
  • [6] Android malware obfuscation variants detection method based on multi-granularity opcode features
    Tang, Junwei
    Li, Ruixuan
    Jiang, Yu
    Gu, Xiwu
    Li, Yuhua
    Future Generation Computer Systems, 2022, 129 : 141 - 151
  • [7] Android malware obfuscation variants detection method based on multi-granularity opcode features
    Tang, Junwei
    Li, Ruixuan
    Jiang, Yu
    Gu, Xiwu
    Li, Yuhua
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2022, 129 : 141 - 151
  • [8] Enhanced Malicious Traffic Detection in Encrypted Communication Using TLS Features and a Multi-class Classifier Ensemble
    Kondaiah, Cheemaladinne
    Pais, Alwyn Roshan
    Rao, Routhu Srinivasa
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2024, 32 (04)
  • [9] Detection of Malicious Applications on Android OS
    Di Cerbo, Francesco
    Girardello, Andrea
    Michahelles, Florian
    Voronkova, Svetlana
    COMPUTATIONAL FORENSICS, 2011, 6540 : 138 - +
  • [10] Feature-based Malicious URL and Attack Type Detection Using Multi-class Classification
    Patil, Dharmaraj R.
    Patil, Jayantrao B.
    ISECURE-ISC INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2018, 10 (02): : 141 - 162