Cross-device behavioral consistency: Benchmarking and implications for effective android malware detection

被引:2
|
作者
Guerra-Manzanares, Alejandro [1 ]
Valbe, Martin [1 ]
机构
[1] Tallinn Univ Technol, Dept Software Sci, Tallinn, Estonia
来源
关键词
Benchmark; Android malware; Malware detection; Malware behavior; System calls; Real device; Android emulator; SYSTEM;
D O I
10.1016/j.mlwa.2022.100357
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Most of the proposed solutions using dynamic features for Android malware detection collect and test their systems using a single and particular data collection device, either a real device or an emulator. The results obtained using these particular devices are then generalized to any Android platform. This extensive generalization is based on the assumption of consistent behavior of apps across devices. This study performs an extensive benchmarking of this assumption for system calls, executing Android malware and benign samples under the same conditions in 9 different collection devices, including real and virtual devices. The results indicate the existence of significant differences between real devices and emulators in system calls usage and, consequently, in the collected behavioral profiles obtained from running the same set of applications on different devices. Furthermore, the impact of these differences on machine learning-based malware detection models is evaluated. In this regard, a significant degenerative effect on the detection performance of the model is produced when data collected on different devices are used in the training and testing sets. Therefore, the empirical findings do not support the assumption of cross-device consistent behavior of Android apps when system calls are used as descriptive features.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] Concept drift and cross-device behavior: Challenges and implications for effective android malware detection
    Guerra-Manzanares, Alejandro
    Luckner, Marcin
    Bahsi, Hayretdin
    [J]. COMPUTERS & SECURITY, 2022, 120
  • [2] Concept drift and cross-device behavior: Challenges and implications for effective android malware detection (vol 120, 102757, 2022)
    Guerra-Manzanares, Alejandro
    Luckner, Marcin
    Bahsi, Hayretdin
    [J]. COMPUTERS & SECURITY, 2023, 124
  • [3] Cross-Device Integration of Android Apps
    Wolters, Dennis
    Kirchhoff, Jonas
    Gerth, Christian
    Engels, Gregor
    [J]. SERVICE-ORIENTED COMPUTING, (ICSOC 2016), 2016, 9936 : 171 - 185
  • [4] Cross-Device Record and Replay for Android Apps
    Li, Cong
    Jiang, Yanyan
    Xu, Chang
    [J]. PROCEEDINGS OF THE 30TH ACM JOINT MEETING EUROPEAN SOFTWARE ENGINEERING CONFERENCE AND SYMPOSIUM ON THE FOUNDATIONS OF SOFTWARE ENGINEERING, ESEC/FSE 2022, 2022, : 395 - 407
  • [5] Behavioral Malware Detection Approaches for Android
    Amin, Mohammad Ram
    Zaman, Mehedee
    Hossain, Md. Shohrab
    Atiquzzamant, Mohammed
    [J]. 2016 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2016,
  • [6] Benchmarking Open-Source Android Malware Detection Tools
    Samara, Mohammed
    El-Ally, El-Sayed M.
    [J]. 2019 2ND IEEE MIDDLE EAST AND NORTH AFRICA COMMUNICATIONS CONFERENCE (IEEEMENACOMM'19), 2019, : 60 - 65
  • [7] "Andromaly": a behavioral malware detection framework for android devices
    Shabtai, Asaf
    Kanonov, Uri
    Elovici, Yuval
    Glezer, Chanan
    Weiss, Yael
    [J]. JOURNAL OF INTELLIGENT INFORMATION SYSTEMS, 2012, 38 (01) : 161 - 190
  • [8] “Andromaly”: a behavioral malware detection framework for android devices
    Asaf Shabtai
    Uri Kanonov
    Yuval Elovici
    Chanan Glezer
    Yael Weiss
    [J]. Journal of Intelligent Information Systems, 2012, 38 : 161 - 190
  • [9] A Lightweight On-Device Detection Method for Android Malware
    Yuan, Wei
    Jiang, Yuan
    Li, Heng
    Cai, Minghui
    [J]. IEEE TRANSACTIONS ON SYSTEMS MAN CYBERNETICS-SYSTEMS, 2021, 51 (09): : 5600 - 5611
  • [10] Sequencing System Calls for Effective Malware Detection in Android
    Ahsan-Ul-Haque, A. S. M.
    Hossain, Md. Shohrab
    Atiquzzaman, Mohammed
    [J]. 2018 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2018,