Lightweight, Obfuscation-Resilient Detection and Family Identification of Android Malware

Lightweight, Obfuscation-Resilient Detection and Family Identification of Android Malware
复制标题

DOI:
10.1145/3162625
复制
发表时间:
2018-01-01
影响因子:
4.4
通讯作者:
Malek, Sam
Malek, Sam
中科院分区:
计算机科学1区
文献类型:
--
作者:
Garcia, Joshua;Hammad, Mahmoud;Malek, Sam

文献摘要

被引文献

相似文献

恶意安卓应用程序的数量正在迅速增加。Android恶意软件可能会损坏或更改其他文件或设置、安装其他应用程序等。要确定此类行为,安全分析师可以通过识别Android恶意软件所属的家族而不是只检测应用程序是否恶意来显著受益。用于检测Android恶意软件并确定其家族的技术,缺乏处理某些旨在阻止检测的混淆的能力。为了解决这些问题,我们提出了一种基于机器学习的Android恶意软件检测和家族识别方法RevelDroid,该方法不需要执行复杂的程序分析或提取大量特征集。具体地说,我们选择的功能利用了分类的Android API使用情况、基于反射的功能以及应用程序的本机二进制文件中的功能。我们使用一个由54,000多个恶意和良性应用程序组成的大型数据集,评估RevelDroid的准确性、效率和混淆恢复能力。我们的实验表明,RevelDroid在检测恶意软件方面的准确率为98%,在确定其家庭成员身份方面的准确率为95%。我们进一步展示了RevelDroid相对于最先进的方法的优越性。
The number of malicious Android apps is increasing rapidly. Android malware can damage or alter other files or settings, install additional applications, and so on. To determine such behaviors, a security analyst can significantly benefit from identifying the family to which an Android malware belongs rather than only detecting if an app is malicious. Techniques for detecting Android malware, and determining their families, lack the ability to handle certain obfuscations that aim to thwart detection. Moreover, some prior techniques face scalability issues, preventing them from detecting malware in a timely manner.To address these challenges, we present a novel machine-learning-based Android malware detection and family identification approach, RevealDroid, that operates without the need to perform complex program analyses or to extract large sets of features. Specifically, our selected features leverage categorized Android API usage, reflection-based features, and features from native binaries of apps. We assess RevealDroid for accuracy, efficiency, and obfuscation resilience using a large dataset consisting of more than 54,000 malicious and benign apps. Our experiments show that RevealDroid achieves an accuracy of 98% in detection of malware and an accuracy of 95% in determination of their families. We further demonstrate RevealDroid's superiority against state-of-the-art approaches.