DAMBA: Detecting Android Malware by ORGB Analysis

DAMBA: Detecting Android Malware by ORGB Analysis
复制标题

DAMBA:通过 ORRGB 分析检测 Android 恶意软件

DOI:
10.1109/tr.2019.2924677
复制
发表时间:
2020-02
影响因子:
5.9
通讯作者:
Peng Liu
Peng Liu
中科院分区:
计算机科学2区
文献类型:
--
作者:
Weizhe Zhang;Huanran Wang;Hui He;Peng Liu

文献摘要

参考文献

被引文献

相似文献

随着智能设备的快速发展,移动的手机已经渗透到我们生活的许多方面。不幸的是,它们的广泛普及吸引了对用户构成严重威胁的无休止的攻击。作为市场份额最大的移动的系统,Android早已成为多年来的重灾区。为了通过ORGB分析检测Android恶意软件,本文提出了一个基于C/S架构的原型系统DAMBA。DAMBA提取应用程序的静态和动态特征。为了进一步分析,我们提出了TANMAD算法,一个两步的Android恶意软件检测算法,它减少了可能的恶意软件家族的范围,然后利用子图同构匹配进行恶意软件检测。本文的主要新奇在于通过构造有向图来对对象引用信息进行建模,称为对象引用图胎记(ORGB)。为了达到更好的效率和准确性,本文提出了几种优化策略的混合分析。DAMBA是在一个包含2239个恶意应用程序和1000个流行良性应用程序的大型真实数据集上进行评估的。在大多数情况下,检测准确率达到100%,平均检测时间小于5 s。实验结果表明,DAMBA的性能优于著名的检测器,McAfee,这是基于签名识别。此外,DAMBA被证明可以有效地抵抗已知的恶意软件攻击及其变种,以及使用混淆技术的恶意软件。
With the rapid development of smart devices, mobile phones have permeated many aspects of our life. Unfortunately, their widespread popularization attracted endless attacks that are serious threats for users. As the mobile system with the largest market share, Android has already become the hardest hit for years. To Detect Android Malware by ORGB Anlysis, in this paper, we present DAMBA, a novel prototype system based on a C/S architecture. DAMBA extracts the static and dynamic features of apps. For further analyses, we propose TANMAD algorithm, a two-step Android malware detection algorithm, which reduces the range of possible malware families, and then utilizes subgraph isomorphism matching for malware detection. The key novelty of this paper is the modeling of object reference information by constructing directed graphs, which is called object reference graph birthmarks (ORGB). To achieve better efficiency and accuracy, in this paper, we present several optimization strategies for hybrid analysis. DAMBA is evaluated on a large real-world dataset of 2239 malicious and 1000 popular benign apps. The detection accuracy reaches 100% in most cases, and the average detection time is less than 5 s. Experimental results show that DAMBA outperforms the well-known detector, McAfee, which is based on signature recognition. In addition, DAMBA is demonstrated to resist the known malware attacks and their variants efficiently, as well as malware that uses obfuscation techniques.
DOI: --
发表时间: 2001
期刊: --
影响因子: --
作者:
L. Cordella;P. Foggia;Carlo Sansone;M. Vento
通讯作者: L. Cordella;P. Foggia;Carlo Sansone;M. Vento
DOI: --
发表时间: 2012
期刊: --
影响因子: --
作者:
Michael C. Grace;Yajin Zhou;Zhi Wang;Xuxian Jiang
通讯作者: Michael C. Grace;Yajin Zhou;Zhi Wang;Xuxian Jiang
DOI: 10.1109/compsac.2015.103
发表时间: 2015-07
期刊: 2015 IEEE 39th Annual Computer Software and Applications Conference
影响因子: --
作者:
Martina Lindorfer;M. Neugschwandtner;Christian Platzer
通讯作者: Martina Lindorfer;M. Neugschwandtner;Christian Platzer
基于Android平台的个人隐私信息保护系统
DOI: 10.1007/s00779-016-0966-0
发表时间: 2016-11
影响因子: --
作者:
Zhang Weizhe;Li Xiong;Xiong Naixue;Vasilakos Athanasios V.
通讯作者: Vasilakos Athanasios V.
DOI: --
发表时间: 2015-08
期刊: --
影响因子: --
作者:
Kai Chen;Peng Wang;Yeonjoon Lee;Xiaofeng Wang;N. Zhang;Heqing Huang;Wei Zou;Peng Liu
通讯作者: Kai Chen;Peng Wang;Yeonjoon Lee;Xiaofeng Wang;N. Zhang;Heqing Huang;Wei Zou;Peng Liu