Android malware detection with contrasting permission patterns

Android malware detection with contrasting permission patterns
复制标题

DOI:
10.1109/cc.2014.6911083
复制
发表时间:
2014
影响因子:
4.1
通讯作者:
Xiong Ping;Xiaofeng Wang;Wenjia Niu;Tianqing Zhu;Li Gang
Xiong Ping;Xiaofeng Wang;Wenjia Niu;Tianqing Zhu;Li Gang
中科院分区:
计算机科学3区
文献类型:
--
作者:
Xiong Ping;Xiaofeng Wang;Wenjia Niu;Tianqing Zhu;Li Gang

文献摘要

被引文献

相似文献

随着Android平台恶意软件风险的急剧增加,Android恶意软件检测成为一个重要的研究课题。现有的工作已经证明,Android应用程序所需的权限是有价值的恶意软件分析,但如何利用这些权限模式的恶意软件检测仍然是一个悬而未决的问题。本文通过引入对比的权限模式,从权限的角度来刻画恶意软件和干净应用程序的本质区别。然后提出了一个基于对比权限模式的Android恶意软件检测框架。根据所提出的框架,集成分类器,Enclamald,进一步发展,以检测是否有潜在的恶意应用程序。Enclamald将每一个不同的权限模式作为一个弱分类器,将所涉及的弱分类器的加权预测聚合为最终结果。在实际应用中的实验验证了所提出的Enclamald分类器优于常用的Android恶意软件检测分类器。
As the risk of malware is sharply increasing in Android platform, Android malware detection has become an important research topic. Existing works have demonstrated that required permissions of Android applications are valuable for malware analysis, but how to exploit those permission patterns for malware detection remains an open issue. In this paper, we introduce the contrasting permission patterns to characterize the essential differences between malwares and clean applications from the permission aspect. Then a framework based on contrasting permission patterns is presented for Android malware detection. According to the proposed framework, an ensemble classifier, Enclamald, is further developed to detect whether an application is potentially malicious. Every contrasting permission pattern is acting as a weak classifier in Enclamald, and the weighted predictions of involved weak classifiers are aggregated to the final result. Experiments on real-world applications validate that the proposed Enclamald classifier outperforms commonly used classifiers for Android Malware Detection.