Effective detection of android malware based on the usage of data flow APIs and machine learning

Effective detection of android malware based on the usage of data flow APIs and machine learning
复制标题

基于数据流 API 和机器学习的使用有效检测 Android 恶意软件

DOI:
10.1016/j.infsof.2016.03.004
复制
发表时间:
2016-07-01
影响因子:
3.9
通讯作者:
Zhang, Yong
Zhang, Yong
中科院分区:
计算机科学2区
文献类型:
--
作者:
Wu, Songyang;Wang, Pan;Zhang, Yong

文献摘要

被引文献

相似文献

上下文Android已被列为当今顶级智能手机平台。研究表明,Android恶意软件急剧增加,个人隐私窃取已成为近年来的主要攻击形式。这些关键的安全环境已经引起了开发自动检测Android应用程序(应用程序)中恶意行为的系统的强烈兴趣。然而,大多数检测敏感数据泄漏的方法都有一定的缺点,包括计算开销和误报。本研究提出一个Android恶意软件侦测系统,提供高度准确的分类和有效的敏感数据传输分析。该研究采用机器学习方法,利用数据流应用程序接口(API)作为分类功能来检测Android恶意软件。我们进行了深入的分析,以提取低相关的API级别的功能和改进的k-近邻分类模型。通过机器学习进一步优化了与XML相关的API列表,大大提高了敏感数据传输分析的效率,而分析精度接近于使用完整的XML相关API列表的实验结果。该方案使用1160良性和1050恶意样本进行评估。实验结果表明,该系统对未知Android恶意软件的检测准确率高达97.66%.静态数据流分析实验表明,改进后的API子集可以确定85%以上的敏感数据传输路径,而分析时间减少了近40%。使用Android相关API是识别Android恶意软件的有效功能。该方案提供了一种有效的方法来检测Android恶意软件和调查恶意应用程序中的隐私侵犯行为。(C)2016爱思唯尔B. V.保留所有权利。
Context. Android has been ranked as the top smartphone platform nowadays. Studies show that Android malware have increased dramatically and that personal privacy theft has become a major form of attack in recent years. These critical security circumstances have generated a strong interest in developing systems that automatically detect malicious behaviour in Android applications (apps). However, most methods of detecting sensitive data leakage have certain shortcomings, including computational expensiveness and false positives.Objective. This study proposes an Android malware detecting system that provides highly accurate classification and efficient sensitive data transmission analysis.Method. The study adopts a machine learning approach that leverages the use of dataflow application program interfaces (APIs) as classification features to detect Android malware. We conduct a thorough analysis to extract dataflow-related API-level features and improve the k-nearest neighbour classification model. The dataflow-related API list is further optimized through machine learning, which enables us to improve considerably the efficiency of sensitive data transmission analysis, whereas analytical accuracy is approximated to that of the experiment using a full dataflow-related API list.Results. The proposed scheme is evaluated using 1160 benign and 1050 malicious samples. Results show that the system can achieve an accuracy rate of as high as 97.66% in detecting unknown Android malware. Our experiment of static dataflow analysis shows that more than 85% of sensitive data transmission paths can be determined using the refined API subset, whereas time of analysis decreases by nearly 40%.Conclusion. The usage of dataflow-related APIs is a valid feature for identifying Android malware. The proposed scheme provides an efficient approach to detecting Android malware and investigating privacy violations in malicious apps. (C) 2016 Elsevier B.V. All rights reserved.