arrow
返回

DroidNative: Automating and optimizing detection of Android native code malware variants

delete2017-03-01
delete76
PRE
AI
S
Shahid Alam *
R
Ryan Riley *
陈
陈焰 (Yan Chen)
V
Vaibhav Rastogi
DOI:10.1016/j.cose.2016.11.011delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
According to the Symantec and F-Secure threat reports, mobile malware development in 2013 and 2014 has continued to focus almost exclusively (similar to 99%) on the Android platform. Malware writers are applying stealthy mutations (obfuscations) to create malware variants, thwarting detection by signature-based detectors. In addition, the plethora of more sophisticated detectors making use of static analysis techniques to detect such variants operate only at the bytecode level, meaning that malware embedded in native code goes undetected. A recent study shows that 86% of the most popular Android applications contain native code, making native code malware a plausible threat vector. This paper proposes DroidNative, an Android malware detector that uses specific control flow patterns to reduce the effect of obfuscations and provides automation. As far as we know, DroidNative is the first system that builds cross-platform (x86 and ARM) semantic-based signatures at the Android native code level, allowing the system to detect malware embedded in either bytecode or native code. When tested with a dataset of 5490 samples, DroidNative achieves a detection rate (DR) of 93.57% and a false positive rate of 2.7%. When tested with traditional malware variants, it achieves a DR of 99.48%, compared to the DRs of academic and commercial tools that range from 8.33% to 93.22%. (C) 2016 Elsevier Ltd. All rights reserved.
Keyword:
Android native code
Maiware analysis
Maiware variant detection
Control flow analysis
Data mining
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

University of Wisconsin System 封面图
University of Wisconsin System
学者数:
6.7W
论文数: 5.8W
被引数: 382
G
Gebze Technical University
学者数:
2.7K
论文数: 2.6K
被引数: 2.4K
Q
Qatar University
学者数:
8.9K
论文数: 9.0K
被引数: 16
N
Northwestern University
学者数:
6.2W
论文数: 5.3W
被引数: 3.9K
学者 查看更多机构
引用论文

引用论文

DENDROID: A text mining approach to analyzing and classifying code structures in Android malware families
err2014-03-01
err179
errOAAI
errSuarez-Tangil, Guillermo; Tapiador, Juan E.; Pens-Lopez, Pedro; Blasco, Jorge
err分享
err收藏
Workplace Hypertension Is Associated with Obesity and Family History of Hypertension
err2006-01-01
err0
errOAAI
errKazumasa HARADA; Yuya KARUBE; Hirokazu SARUHARA; Kazuhiro TAKEDA; Iwao KUWAJIMA
err分享
err收藏
Android Security: A Survey of Issues, Malware Penetration, and DefensesAndroid安全: 关于问题、恶意软件渗透和防御的调查
err2015-01-01
err294
errOAAI
errFaruki, Parvez; Bharmal, Ammar; Laxmi, Vijay; Ganmoor, Vijay; Gaur, Manoj Singh; Conti, Mauro; Rajarajan, Muttukrishnan
err分享
err收藏
Detecting mobile malware threats to homeland security through static analysis
err2014-02-01
err113
PREAI
errSeo, Seung-Hyun; Gupta, Aditi; Sallam, Asmaa Mohamed; Bertino, Elisa; Yim, Kangbin
err分享
err收藏
err分享
err收藏
Spatiotemporal variation of groundwater quality using integrated multivariate statistical and geostatistical approaches in Amol–Babol Plain, Iran
err2014-06-04
err0
PREAI
errTahoora Sheikhy Narany; Mohammad Firuz Ramli; Ahmad Zaharin Aris; Wan Nor Azmin Sulaiman; Kazem Fakharian
err分享
err收藏
没有更多内容