Power Consumption-based Application Classification and Malware Detection on Android Using Machine-Learning Techniques

Power Consumption-based Application Classification and Malware Detection on Android Using Machine-Learning Techniques
复制标题

使用机器学习技术在 Android 上进行基于功耗的应用程序分类和恶意软件检测

DOI:
--
复制
发表时间:
2013
期刊:
影响因子:
--
通讯作者:
Andreas Hoeller
Andreas Hoeller
中科院分区:
--
文献类型:
--
作者:
Thomas Zefferer;Peter Teufl;David Derler;Klaus Potzmader;Alexander Oprisnik;Hubert Gasparitz;Andreas Hoeller

文献摘要

被引文献

相似文献

在过去几年中,移动计算的重要性显着增加,预计仍将是未来最相关的计算趋势之一。智能手机是基于移动计算的解决方案的关键组成部分,使最终用户能够方便地访问服务和信息。由于其重要性和受欢迎程度不断提高,智能手机最近已成为恶意软件的常见目标。不幸的是,智能手机上的恶意软件检测应用程序的功能有限,因为沙箱或细粒度权限模型等实施的安全功能限制了第三方应用程序的功能。这些限制阻止恶意软件检测应用程序访问识别恶意软件所需的信息,因此使得在智能手机上实施可靠的恶意软件检测解决方案变得困难。为了解决这个问题,我们提出了一种针对智能手机的替代恶意软件检测方法,该方法依赖于智能手机测量的功耗。我们提出了两种不同的机器学习技术,允许根据应用程序的功耗对应用程序进行分类,从而有助于识别可疑和潜在恶意的软件组件。所提出技术的功能已通过对物理智能手机上运行的实际应用程序进行评估来评估。该评估过程的结果证明了基于功耗的分类和恶意软件检测方法的一般适用性,特别是所提出的两种机器学习技术的适用性。关键词——安卓;功耗;应用分类;恶意软件检测;机器学习
Mobile computing has significantly gained importance during the past years and is expected to remain one of the most relevant future computing trends. Smartphones represent a key component of mobile computing based solutions and allow end users to conveniently access services and information. Due to their continuously growing importance and popularity, smartphones have recently become a common target for malware. Unfortunately, capabilities of malware-detection applications on smartphones are limited, as implemented security features such as sandboxing or fine-grained permission models restrict capabilities of third-party applications. These restrictions prevent malwaredetection applications from accessing information, which is required to identify malware, and hence render the implementation of reliable malware-detection solutions on smartphones difficult. To overcome this issue, we propose an alternative malwaredetection method for smartphones that relies on the smartphone’s measured power consumption. We propose two different machinelearning techniques that allow for a classification of applications according to their power consumption and hence facilitate the identification of suspicious and potentially malicious software components. The capabilities of the proposed techniques have been assessed by means of an evaluation with real-world applications running on physical smartphones. The results of this evaluation process demonstrate the applicability of power consumption based classification and malware-detection approaches in general and of the two proposed machine-learning techniques in particular. Keywords—Android; power consumption; application classification; malware detection; machine learning