arrow
返回

Intrusion detection for mobile devices using the knowledge-based, temporal abstraction method

delete2010-08-01
delete83
PRE
AI
A
Asaf Shabtai *
U
Uri Kanonov
Y
Yuval Elovici
DOI:10.1016/j.jss.2010.03.046delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
In this paper, a new approach for detecting previously unencountered malware targeting mobile device is proposed. In the proposed approach, time-stamped security data is continuously monitored within the target mobile device (i.e., smartphones, PDAs) and then processed by the knowledge-based temporal abstraction (KBTA) methodology. Using KBTA, continuously measured data (e.g., the number of sent SMSs) and events (e.g., software installation) are integrated with a mobile device security domain knowledge-base (i.e., an ontology for abstracting meaningful patterns from raw, time-oriented security data), to create higher level, time-oriented concepts and patterns, also known as temporal abstractions. Automatically-generated temporal abstractions are then monitored to detect suspicious temporal patterns and to issue an alert. These patterns are compatible with a set of predefined classes of malware as defined by a security expert (or the owner) employing a set of time and value constraints. The goal is to identify malicious behavior that other defensive technologies (e.g., antivirus or firewall) failed to detect. Since the abstraction derivation process is complex, the KBTA method was adapted for mobile devices that are limited in resources (i.e., CPU, memory, battery). To evaluate the proposed modified KBTA method a lightweight host-based intrusion detection system (HIDS), combined with central management capabilities for Android-based mobile phones, was developed. Evaluation results demonstrated the effectiveness of the new approach in detecting malicious applications on mobile devices (detection rate above 94% in most scenarios) and the feasibility of running such a system on mobile devices (CPU consumption was 3% on average). (C) 2010 Elsevier Inc. All rights reserved.
Keyword:
Intrusion detection
Mobile devices
Temporal reasoning
Knowledge-based systems
Malware
Android
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

Journal of Systems and Software 封面图
Journal of Systems and Software
IF:
4.1
论文数:
5.4K
被引数:
8.4K

机构

D
deutsche telekom ag
学者数:
172
论文数: 129
被引数: 1
引用论文

引用论文

From desktop to mobile: Examining the security experience
err2009-05-01
err52
PREAI
errBotha, Reinhardt A.; Furnell, Steven M.; Clarke, Nathan L.
err分享
err收藏
Understanding and Modeling of Grain Boundary Pinning in Inconel 718
err2012-10-02
err0
PREAI
errAndrea Agnoli; Marc Bernacki; Roland Logé; Jean‐Michel Franchet; Johanne Laigo; Nathalie Bozzolo
err分享
err收藏
Short report: the effect of misoprostol on the anaemia of NSAID enteropathy
err2007-03-31
err0
PREAI
errA. J. MORRIS; L. MURRAY; R. D. STURROCK; R. MADHOK; H. A. CAPELL; J. F. MACKENZIE
err分享
err收藏
学者 查看更多内容