N-opcode analysis for android malware classification and categorization

N-opcode analysis for android malware classification and categorization
复制标题

DOI:
10.1109/cybersecpods.2016.7502343
复制
发表时间:
2016-07
期刊:
2016 International Conference On Cyber Security And Protection Of Digital Services (Cyber Security)
影响因子:
--
通讯作者:
Boojoong Kang;S. Yerima;K. Mclaughlin;S. Sezer
Boojoong Kang;S. Yerima;K. Mclaughlin;S. Sezer
中科院分区:
其他
文献类型:
--
作者:
Boojoong Kang;S. Yerima;K. Mclaughlin;S. Sezer

文献摘要

被引文献

相似文献

恶意软件检测是一个日益严重的问题,特别是在Android移动的平台上,因为其越来越受欢迎,并且可访问许多第三方应用程序市场。新兴恶意软件家族采用的日益复杂的检测规避技术也使情况变得更糟。这需要更有效的技术来检测和分类Android恶意软件。因此,在本文中,我们提出了一种基于n-opcode分析的方法,该方法利用机器学习对Android恶意软件进行分类和归类。这种方法实现了自动化特征发现,消除了应用专家或领域知识来定义所需特征的需要。我们在2520个样本上进行的实验使用了多达10克的操作码特征,结果表明使用这种方法可以实现98%的f-测量。
Malware detection is a growing problem particularly on the Android mobile platform due to its increasing popularity and accessibility to numerous third party app markets. This has also been made worse by the increasingly sophisticated detection avoidance techniques employed by emerging malware families. This calls for more effective techniques for detection and classification of Android malware. Hence, in this paper we present an n-opcode analysis based approach that utilizes machine learning to classify and categorize Android malware. This approach enables automated feature discovery that eliminates the need for applying expert or domain knowledge to define the needed features. Our experiments on 2520 samples that were performed using up to 10-gram opcode features showed that an f-measure of 98% is achievable using this approach.