arrow
返回

ICCDetector: ICC-Based Malware Detection on Android

delete2016-06-01
delete126
delete
OA
AI
徐恪 封面图
徐恪 (Ke Xu)
Y
Yingjiu Li
R
Robert H. Deng *
DOI:10.1109/TIFS.2016.2523912delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
Most existing mobile malware detection methods (e.g., Kirin and DroidMat) are designed based on the resources required by malwares (e.g., permissions, application programming interface (API) calls, and system calls). These methods capture the interactions between mobile apps and Android system, but ignore the communications among components within or cross application boundaries. As a consequence, the majority of the existing methods are less effective in identifying many typical malwares, which require a few or no suspicious resources, but leverage on inter-component communication (ICC) mechanism when launching stealthy attacks. To address this challenge, we propose a new malware detection method, named ICCDetector. ICCDetector outputs a detection model after training with a set of benign apps and a set of malwares, and employs the trained model for malware detection. The performance of ICCDetector is evaluated with 5264 malwares, and 12 026 benign apps. Compared with our benchmark, which is a permission-based method proposed by Peng et al. in 2012 with an accuracy up to 88.2%, ICCDetector achieves an accuracy of 97.4%, roughly 10% higher than the benchmark, with a lower false positive rate of 0.67%, which is only about a half of the benchmark. After manually analyzing false positives, we discover 43 new malwares from the benign data set, and reduce the number of false positives to seven. More importantly, ICCDetector discovers 1708 more advanced malwares than the benchmark, while it misses 220 obvious malwares, which can be easily detected by the benchmark. For the detected malwares, ICCDetector further classifies them into five newly defined malware categories, which help understand the relationship between malicious behaviors and ICC characteristics. We also provide a systemic analysis of ICC patterns of benign apps and malwares.
Keyword:
ICC
malware detection
Android
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

IEEE Transactions on Information Forensics and Security 封面图
IEEE Transactions on Information Forensics and Security
IF:
8
论文数:
5.2K
被引数:
2.3W

机构

S
Singapore Management University
学者数:
1.5K
论文数: 2.5K
被引数: 3.5K
引用论文

引用论文

The Effects of 12 Weeks Yoga Training on 4-5-Year-Old Preschoolers’ Fitness Components
err2023-04-01
err0
errOAAI
errDung Xuan Phung; Vinh Quang Nguyen; Dai Quang Tran; Truong Ngoc Duong
err分享
err收藏
Heat storage capacity of sodium acetate trihydrate during thermal cycling
err1984-01-01
err0
PREAI
errTakahiro Wada; Ryoichi Yamamoto; Yoshihiro Matsuo
err分享
err收藏
Development of a Rechargeable Zinc-Air Battery
err2010-02-05
err0
errOAAI
errGwenaëlle Toussaint; Philippe Stevens; Florian Moureau; Robert Rouget; Fabrice Fourgeot
err分享
err收藏
Genomewide Analysis of mRNA Processing in Yeast Using Splicing-Specific Microarrays
err2002-05-03
err0
PREAI
errTyson A. Clark; Charles W. Sugnet; Manuel Ares
err分享
err收藏
Quantitative characterization of liquids flowing in geometrically controlled sub-100 nm nanofluidic channels
err2023-03-08
err0
errOAAI
errYutaka Kazoe; Keisuke Ikeda; Kensuke Mino; Kyojiro Morikawa; Kazuma Mawatari; Takehiko Kitamori
err分享
err收藏
学者 查看更多内容