Andro-Dumpsys: Anti-malware system based on the similarity of malware creator and malware centric information

Andro-Dumpsys: Anti-malware system based on the similarity of malware creator and malware centric information
复制标题

DOI:
10.1016/j.cose.2015.12.005
复制
发表时间:
2016-05
期刊:
Comput. Secur.
影响因子:
--
通讯作者:
Jae-wook Jang;Hyunjae Kang;Jiyoung Woo;Aziz Mohaisen;H. Kim
Jae-wook Jang;Hyunjae Kang;Jiyoung Woo;Aziz Mohaisen;H. Kim
中科院分区:
其他
文献类型:
--
作者:
Jae-wook Jang;Hyunjae Kang;Jiyoung Woo;Aziz Mohaisen;H. Kim

文献摘要

被引文献

相似文献

随着移动技术的快速发展以及这些技术融入我们日常生活的兴起,移动安全被视为最突出的领域之一,并正在得到相应的解决。为此,特别是为了解决与恶意软件相关的威胁,文献中开发了各种以恶意软件为中心的分析方法,以识别、分类和防御移动威胁和恶意行为者。然而,随着这种发展,反恶意软件分析技术,如打包、动态加载和索引加密,已经被广泛采用,使得现有的以恶意软件为中心的分析方法不那么有效。在本文中,我们提出了一个功能丰富的混合反恶意软件系统,称为android - dumpsys,它利用易失性存储器采集来准确检测和分类恶意软件。android - dumpsys基于恶意软件创建者中心和恶意软件中心信息的相似性匹配。利用android - dumpsys,我们通过利用它们的足迹(相当于独特的行为特征)来检测恶意软件样本并将其分类为相似的行为组。实验结果表明,android - dumpsys具有良好的可扩展性,在检测恶意软件和分类恶意软件家族方面表现良好,具有较低的假阳性和假阴性,并且能够响应零日威胁。
With the fast growth in mobile technologies and the accompanied rise of the integration of such technologies into our everyday life, mobile security is viewed as one of the most prominent areas and is being addressed accordingly. For that, and especially to address the threat associated with malware, various malware-centric analysis methods are developed in the literature to identify, classify, and defend against mobile threats and malicious actors. However, along with this development, anti-malware analysis techniques, such as packing, dynamic loading, and dex encryption, have seen wide adoption, making existing malware-centric analysis methods less effective. In this paper, we propose a feature-rich hybrid anti-malware system, called Andro-Dumpsys, which leverages volatile memory acquisition for accurate malware detection and classification. Andro-Dumpsys is based on similarity matching of malware creator-centric and malware-centric information. Using Andro-Dumpsys, we detect and classify malware samples into similar behavior groups by exploiting their footprints, which are equivalent to unique behavior characteristics. Our experimental results demonstrate that Andro-Dumpsys is scalable, and performs well in detecting malware and classifying malware families with low false positives and false negatives, and is capable of responding zero-day threats.