Identifying Android malware with system call co‐occurrence matrices

Identifying Android malware with system call co‐occurrence matrices
复制标题

DOI:
10.1002/ett.3016
复制
发表时间:
2016-05
影响因子:
3.6
通讯作者:
Xi Xiao;Xianni Xiao;Yong Jiang;Xuejiao Liu;Runguo Ye
Xi Xiao;Xianni Xiao;Yong Jiang;Xuejiao Liu;Runguo Ye
中科院分区:
计算机科学4区
文献类型:
--
作者:
Xi Xiao;Xianni Xiao;Yong Jiang;Xuejiao Liu;Runguo Ye

文献摘要

相似文献

随着Android设备的普及,Android中的移动的恶意软件变得更加普遍。恶意软件会对用户造成很多伤害,例如窃取个人信息,使用过多的电池或CPU。检测移动的恶意软件是Android安全的主要任务。在这项工作中,我们使用动态分析方法来区分恶意软件与系统调用序列。首先,我们跟踪应用程序在不同事件下的系统调用。然后采用两种不同的特征模型,频率向量和共生矩阵,从系统调用序列中提取特征。最后,我们应用自适应正则化的权重向量和其他机器学习算法来识别Android恶意软件的基础上上述两个模型,分别。我们评估我们的方法与1189良性应用程序和1227恶意应用程序。实验结果表明,共生矩阵可以实现比频率向量更好的检测率。最佳检测率为97.7%,假阳性率为1.34%,优于现有方法。版权所有© 2016约翰威利父子有限公司.
With the popularity of Android devices, mobile malware in Android has became more prevalent. Malware causes lots of harm to users, such as stealing personal information and using too much battery or CPU. Detecting mobile malware is the main task in Android security. In this work, we use a dynamic analysis method to distinguish malware with system call sequences. At first, we track the system calls of applications under different events. Then two different feature models, the frequency vector and the co‐occurrence matrix, are employed to extract features from the system call sequence. Finally, we apply Adaptive Regularization Of Weight Vectors and other machine learning algorithms to identify Android malware based on the aforementioned two models, respectively. We evaluate our method with 1189 benign applications and 1227 malicious applications. The experiment results show that the co‐occurrence matrix can achieve a much better detection rate than the frequency vector. Our best detection rate is 97.7per cent with false positive rate being 1.34per cent, which is better than those of the existing methods. Copyright © 2016 John Wiley & Sons, Ltd.