arrow
Return

DroidChain: A novel Android malware detection method based on behavior chains

delete2016-10-01
delete22
PRE
AI
Z
Zhaoguo Wang *
C
Chenglong Li
Z
Zhenlong Yuan
Y
Yi Guan
Y
Yibo Xue
DOI:10.1016/j.pmcj.2016.06.018delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The drastic increase of Android malware has led to strong interest in automating malware analysis. In this paper, to fight against malware variants and zero-day malware, we proposed DroidChain: a method combining static analysis and a behavior chain model. We transform the malware detection problem into more accessible matrix form. Using this method, we propose four kinds of malware models, including privacy leakage, SMS financial charges, malware installation, and privilege escalation. To reduce time complexity, we propose the WxShall-extend algorithm. We had moved the prototype to GitHub and evaluate using 1260 malware samples. Experimental malware detection results demonstrate accuracy, precision, and recall of 73%-93%, 71%-99%, and 42%-92%, respectively. Calculation time accounts for 6.58% of the well-known Warshall algorithm's expense. Results demonstrate that our method, which can detect four kinds of malware simultaneously, is better than Androguard and Kirin. (C) 2016 Elsevier B.V. All rights reserved.
Keywords:
Android malware
Behavior chain
Privacy leakage
SMS financial charge
Malware installation
Privilege escalation
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

Pervasive and Mobile Computing cover
Pervasive and Mobile Computing
IF:
3.5
Papers:
1.5K
Citations:
2.2K

Organization

H
harbin institute of technology
Scholars:
8.0W
Papers: 6.6W
Citations: 66
T
tsinghua university
Scholars:
11.8W
Papers: 10.0W
Citations: 137