arrow
返回

IntDroid: Android Malware Detection Based on API Intimacy Analysis

delete2021-05-08
delete32
PRE
AI
D
Deqing Zou
Y
Yueming Wu *
S
Siru Yang
A
Anki Chauhan
W
Wei Yang
J
Jiangying Zhong
S
Shihan Dou
金
金海 (Hai Jin)
DOI:10.1145/3442588delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Android, the most popular mobile operating system, has attracted millions of users around the world. Meanwhile, the number of new Android malware instances has grown exponentially in recent years. On the one hand, existing Android malware detection systems have shown that distilling the program semantics into a graph representation and detecting malicious programs by conducting graph matching are able to achieve high accuracy on detecting Android malware. However, these traditional graph-based approaches always perform expensive program analysis and suffer from low scalability on malware detection. On the other hand, because of the high scalability of social network analysis, it has been applied to complete large-scale malware detection. However, the social-network-analysis-based method only considers simple semantic information (i.e., centrality) for achieving market-wide mobile malware scanning, which may limit the detection effectiveness when benign apps show some similar behaviors as malware. In this article, we aim to combine the high accuracy of traditional graph-based method with the high scalability of social-network-analysis-based method for Android malware detection. Instead of using traditional heavyweight static analysis, we treat function call graphs of apps as complex social networks and apply social-network-based centrality analysis to unearth the central nodes within call graphs. After obtaining the central nodes, the average intimacies between sensitive API calls and central nodes are computed to represent the semantic features of the graphs. We implement our approach in a tool called IntDroid and evaluate it on a dataset of 3,988 benign samples and 4,265 malicious samples. Experimental results show that IntDroid is capable of detecting Android malware with an F-measure of 97.1% while maintaining a True-positive Rate of 99.1%. Although the scalability is not as fast as a social-network-analysis-based method (i.e., MalScan), compared to a traditional graph-based method, IntDroid is more than six times faster than MaMaDroid. Moreover, in a corpus of apps collected from GooglePlay market, IntDroid is able to identify 28 zero-day malware that can evade detection of existing tools, one of which has been downloaded and installed by more than ten million users. This app has also been flagged as malware by six anti-virus scanners in VirusTotal, one of which is Symantec Mobile Insight.
Keyword:
Android malware
API intimacy
social network
centrality
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

A
ACM Transactions on Software Engineering and Methodology
IF:
6.2
论文数:
1.2K
被引数:
3.4K

机构

U
University of Texas Dallas
学者数:
5.6K
论文数: 5.0K
被引数: 15
U
university of texas system
学者数:
18.5W
论文数: 15.6W
被引数: 210
引用论文

引用论文

err分享
err收藏
Patterns of cerebral cortex mRNA expression
err2004-10-11
err0
PREAI
errJ. Bernal; M. Godbout; K. W. Hasel; G. H. Travis; J. G. Sutcliffe
err分享
err收藏
Multicenter three-distorted-wave approach to three-dimensional images for electron-impact-ionization dynamics of molecules: Overall agreement with experiment
err2018-10-29
err0
PREAI
errMaomao Gong; Xingyu Li; Song Bin Zhang; Shanshan Niu; Xueguang Ren; Enliang Wang; Alexander Dorn; Xiangjun Chen
err分享
err收藏
Development of a Rechargeable Zinc-Air Battery
err2010-02-05
err0
errOAAI
errGwenaëlle Toussaint; Philippe Stevens; Florian Moureau; Robert Rouget; Fabrice Fourgeot
err分享
err收藏
THE ENZYMATIC REDUCTION OF Δ4-3-KETOSTEROIDS
err1957-03-01
err0
errOAAI
errGordon M. Tomkins; Patricia J. Michael
err分享
err收藏
Investigating Team Learning in a Military Context
err2013-11-21
err0
PREAI
errMarlies Veestraeten; Eva Kyndt; Filip Dochy
err分享
err收藏
err分享
err收藏
err分享
err收藏
学者 查看更多内容