arrow
返回

Obfuscation-Resilient Android Malware Analysis Based on Complementary Features

delete2023-01-01
delete14
PRE
AI
C
Cuiying Gao
M
Minghui Cai
S
S.Y. Yin
G
G. Huang
H
Heng Li
W
Wei Yuan *
X
Xiapu Luo
DOI:10.1109/TIFS.2023.3302509delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Existing Android malware detection methods are usually hard to simultaneously resist various obfuscation techniques. Therefore, bytecode-based code obfuscation becomes an effective means to circumvent Android malware analysis. Building obfuscation-resilient Android malware analysis methods is a challenging task, due to the fact that various obfuscation techniques have vastly different effects on code and detection features. To mitigate this problem, we propose combining multiple features that are complementary in combating code obfuscation. Accordingly, we develop an obfuscation-resilient Android malware analysis method CorDroid, based on two new features: Enhanced Sensitive Function Call Graph (E-SFCG) and Opcode-based Markov transition Matrix (OMM). The first describes sensitive function call relationships, while the second reflects transition probabilities among opcodes. Combining E-SFCG and OMM can well characterize the runtime behavior of Android apps from different perspectives, hence increasing the difficulty of misleading malware analysis through using code obfuscation to affect detection features. To evaluate CorDroid, we generate 74, 138 obfuscated samples with 14 different obfuscation techniques, and compare CorDroid with the state-of-the-art detection methods (e.g., MaMaDroid, RevealDroid and APIGraph). In terms of average F1-Score, CorDroid is 29.69% higher than MaMaDroid, 21.80% higher than APIGraph, and 9.71% higher than RevealDroid, respectively. Experiments also validate the complementarity between E-SFCG and OMM, and exhibit the high execution efficiency of CorDroid.
Keyword:
Android malware analysis
code obfuscation
complementary features

期刊

IEEE Transactions on Information Forensics and Security 封面图
IEEE Transactions on Information Forensics and Security
IF:
8
论文数:
5.3K
被引数:
2.3W

机构

暂无机构信息
引用论文

引用论文

err分享
err收藏
A Deep Dive Inside DREBIN: An Explorative Analysis beyond Android Malware Detection Scores
err2022-05-04
err15
errOAAI
errDaoudi, Nadia; Allix, Kevin; Bissyande, Tegawende Francois; Klein, Jacques
err分享
err收藏
THE ENZYMATIC REDUCTION OF Δ4-3-KETOSTEROIDS
err1957-03-01
err0
errOAAI
errGordon M. Tomkins; Patricia J. Michael
err分享
err收藏
EMG map image processing for recognition of fingers movement
err2019-12-01
err0
errOAAI
errIvan Topalović; Stevica Graovac; Dejan B. Popović
err分享
err收藏
Investigating Team Learning in a Military Context
err2013-11-21
err0
PREAI
errMarlies Veestraeten; Eva Kyndt; Filip Dochy
err分享
err收藏
Genomewide Analysis of mRNA Processing in Yeast Using Splicing-Specific Microarrays
err2002-05-03
err0
PREAI
errTyson A. Clark; Charles W. Sugnet; Manuel Ares
err分享
err收藏
DAPASA: Detecting Android Piggybacked Apps Through Sensitive Subgraph Analysis
err2017-08-01
err110
PREAI
errFan, Ming; Liu, Jun; Wang, Wei; Li, Haifei; Tian, Zhenzhou; Liu, Ting
err分享
err收藏
学者 查看更多内容