Return
SWORD: Semantic aWare andrOid malwaRe Detector
DOI:10.1016/j.jisa.2018.07.003.png)
Abstract
En 中文
Malicious android applications have become more advanced and severe threat to user privacy, confidentiality, integrity, money, and device. The process of malware evolution mainly consists of modifications to existing malware using repackaging of apps employing polymorphism, metamorphism and injecting malicious code. The existing dynamic approaches can handle polymorphism, metamorphism and repacking of apps but failed to address code injection at runtime, as it modifies the control/data flow. In this paper, we present a semantic aware dynamic malware detection tool, SWORD. It encapsulates the semantics of Android apps in such a way that makes it resilient towards injection-based evasion techniques. The intuition behind specifying the semantics of apps lies in applying Asymptotic Equipartition Property (AEP) inherited from information theory domain. The semantics of the app are captured using a sequence of system-calls. To assess the efficacy of SWORD, we carried out comprehensive experiments on 60 0 0 execution traces of 20 0 0 applications (10 0 0 malware apps belonging to 119 different families and 10 0 0 benign apps, selected randomly from 12,0 0 0 Google Play store apps). We obtain a detection accuracy of 94.2%. Moreover, we show that SWORD can cope with the code injection based evasion techniques. (c) 2018 Elsevier Ltd. All rights reserved.
Keywords:
Android
Malware analysis
Semantic analysis
Information leakage
AI Summary
Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.
Journal
IF:
3.7
Papers:
1.9K
Citations:
4.9K

