Object Allocation Pattern as an Indicator for Maliciousness - An Exploratory Analysis
Object Allocation Pattern as an Indicator for Maliciousness - An Exploratory Analysis
复制标题
对象分配模式作为恶意指标 - 探索性分析
DOI:
10.1145/3422337.3450322
复制
发表时间:
2021
期刊:
影响因子:
--
通讯作者:
Ali-Gombe, Aisha
中科院分区:
文献类型:
--
作者:
Hussaini, Adamu;Zahran, Bassam;Ali-Gombe, Aisha
Traditionally, Android malware is analyzed using static or dynamic analysis. Although static techniques are often fast; however, they cannot be applied to classify obfuscated samples or malware with a dynamic payload. In comparison, the dynamic approach can examine obfuscated variants but often incurs significant runtime overhead when collecting every important malware behavioral data. This paper conducts an exploratory analysis of memory forensics as an alternative technique for extracting feature vectors for an Android malware classifier. We utilized the reconstructed per-process object allocation network to identify distinguishable patterns in malware and benign application. Our evaluation results indicate the network structural features in the malware category are unique compared to the benign dataset, and thus features extracted from the remnant of in-memory allocated objects can be utilized for robust Android malware classification algorithm.
DOI:
10.1145/3427228.3427244
发表时间:
2020-12
期刊:
Proceedings of the 36th Annual Computer Security Applications Conference
影响因子:
--
作者:
Aisha I. Ali-Gombe;Alexandra Tambaoan;Angela Gurfolino;G. Richard
通讯作者:
Aisha I. Ali-Gombe;Alexandra Tambaoan;Angela Gurfolino;G. Richard
DOI:
--
发表时间:
2019
期刊:
RAID 2019
影响因子:
--
作者:
Ali-Gombe, A.;Sudhakaran, S.;Case, A.;Richard, G.
通讯作者:
Richard, G.