Analysis of Mobile P2P Malware Detection Framework through Cabir & Commwarrior Families

Analysis of Mobile P2P Malware Detection Framework through Cabir & Commwarrior Families
复制标题

DOI:
10.1109/passat/socialcom.2011.243
复制
发表时间:
2011-10
期刊:
2011 IEEE Third Int'l Conference on Privacy, Security, Risk and Trust and 2011 IEEE Third Int'l Conference on Social Computing
影响因子:
--
通讯作者:
M. Adeel;L. Tokarchuk
M. Adeel;L. Tokarchuk
中科院分区:
其他
文献类型:
--
作者:
M. Adeel;L. Tokarchuk

文献摘要

被引文献

相似文献

近年来,移动对等(P2P)恶意软件已成为移动网络安全面临的主要挑战之一。到目前为止,已经发现了大约400种移动病毒、蠕虫、特洛伊木马和间谍软件,以及大约1000种它们的变体。到目前为止,还没有对这种移动P2P安全威胁进行分类。目前还没有一个广为人知的仿真环境来模拟移动P2P网络的特征,并为分析不同类型的移动恶意软件的传播提供平台。因此,我们的研究基于节点在感染过程中的行为对移动恶意软件进行了分类,并开发了一个分析恶意软件传播的平台。它提出并评估了一种新的基于行为的方法,使用人工智能来检测各种恶意软件家族。与现有方法不同,我们的方法侧重于识别和分类恶意软件家族,而不是检测单个恶意软件及其变体。通过部署的检测框架,在人工智能分类器的帮助下,在指定的移动节点上自适应检测当前已知和以前未知的移动恶意软件,从而实现成功检测。虽然我们已经根据移动P2P恶意软件在感染过程中的行为将大约30%的移动P2P恶意软件分类为13个不同的恶意软件家族,但为了分析所提出的检测框架,本文重点研究了Cabir&Commwarrior这两个恶意软件家族。
Mobile Peer-to-Peer (P2P) malware has emerged as one of the major challenges in mobile network security in recent years. Around four hundred mobile viruses, worms, trojans and spy ware, together with approximately one thousand of their variants have been discovered to-date. So far no classification of such mobile P2P security threats exists. There is no well known simulation environment to model mobile P2P network characteristics and provide a platform for the analysis of the propagation of different types of mobile malware. Therefore, our research provides a classification of mobile malware based on the behaviour of a node during infection and develops a platform to analyse malware propagation. It proposes and evaluates a novel behaviour-based approach, using AI, for the detection of various malware families. Unlike existing approaches, our approach focuses on identifying and classifying malware families rather than detecting individual malware and their variants. Adaptive detection of currently known and previously unknown mobile malware on designated mobile nodes through a deployed detection framework aided by AI classifiers enables successful detection. Although we have classified around 30% of the existing mobile P2P malware into 13 distinct malware families based on their behaviour during infection, this paper focuses on two, Cabir & Commwarrior, in order to analyse the proposed detection framework.