Static Analysis of Executables for Collaborative Malware Detection on Android

Static Analysis of Executables for Collaborative Malware Detection on Android
复制标题

DOI:
10.1109/icc.2009.5199486
复制
发表时间:
2009-06
期刊:
2009 IEEE International Conference on Communications
影响因子:
--
通讯作者:
Aubrey-Derrick Schmidt;Rainer Bye;Hans-Gunther Schmidt;J. Clausen;Osman Kiraz;Kamer Ali Yüksel;S. Çamtepe-S
Aubrey-Derrick Schmidt;Rainer Bye;Hans-Gunther Schmidt;J. Clausen;Osman Kiraz;Kamer Ali Yüksel;S. Çamtepe-S
中科院分区:
其他
文献类型:
--
作者:
Aubrey-Derrick Schmidt;Rainer Bye;Hans-Gunther Schmidt;J. Clausen;Osman Kiraz;Kamer Ali Yüksel;S. Çamtepe-S

文献摘要

被引文献

相似文献

智能手机越来越受欢迎,并且出现了一些针对这些设备的恶意软件。目前,智能手机恶意软件的一般对策仅限于基于签名的防病毒扫描仪,这些扫描仪有效地检测到已知的恶意软件,但它们具有严重的缺点,而新的和未知的恶意软件为攻击者创造了机会窗口。随着智能手机成为敏感数据和应用程序的主机,必须遵守相应的资源约束,扩展的恶意软件检测机制是必要的。本文的贡献是双重的。首先,我们对可执行文件执行静态分析,以使用命令读取在Android环境中提取其函数调用。将功能调用列表与恶意软件可执行文件进行比较,以将其分类为部分,棱镜和最近的邻居算法。其次,我们提出了一种协作恶意软件检测方法,以扩展这些结果。提出了相应的仿真结果。
Smartphones are getting increasingly popular and several malwares appeared targeting these devices. General countermeasures to smartphone malwares are currently limited to signature-based antivirus scanners which efficiently detect known malwares, but they have serious shortcomings with new and unknown malwares creating a window of opportunity for attackers. As smartphones become host for sensitive data and applications, extended malware detection mechanisms are necessary complying with the corresponding resource constraints. The contribution of this paper is twofold. First, we perform static analysis on the executables to extract their function calls in Android environment using the command readelf. Function call lists are compared with malware executables for classifying them with PART, Prism and Nearest Neighbor Algorithms. Second, we present a collaborative malware detection approach to extend these results. Corresponding simulation results are presented.