Dissecting Android Malware: Characterization and Evolution

被引:1149
|
作者
Zhou, Yajin [1 ]
Jiang, Xuxian [1 ]
机构
[1] N Carolina State Univ, Dept Comp Sci, Raleigh, NC 27695 USA
基金
美国国家科学基金会;
关键词
Android malware; smartphone security;
D O I
10.1109/SP.2012.16
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The popularity and adoption of smartphones has greatly stimulated the spread of mobile malware, especially on the popular platforms such as Android. In light of their rapid growth, there is a pressing need to develop effective solutions. However, our defense capability is largely constrained by the limited understanding of these emerging mobile malware and the lack of timely access to related samples. In this paper, we focus on the Android platform and aim to systematize or characterize existing Android malware. Particularly, with more than one year effort, we have managed to collect more than 1,200 malware samples that cover the majority of existing Android malware families, ranging from their debut in August 2010 to recent ones in October 2011. In addition, we systematically characterize them from various aspects, including their installation methods, activation mechanisms as well as the nature of carried malicious payloads. The characterization and a subsequent evolution-based study of representative families reveal that they are evolving rapidly to circumvent the detection from existing mobile anti-virus software. Based on the evaluation with four representative mobile security software, our experiments show that the best case detects 79.6% of them while the worst case detects only 20.2% in our dataset. These results clearly call for the need to better develop next-generation anti-mobile-malware solutions.
引用
收藏
页码:95 / 109
页数:15
相关论文
共 50 条
  • [1] Revealing Similarities in Android Malware by Dissecting their Methods
    Pasetto, Michele
    Marastoni, Niccolo
    Dalla Preda, Mila
    [J]. 2020 IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (EUROS&PW 2020), 2020, : 625 - 634
  • [2] The Evolution of Android Malware and Android Analysis Techniques
    Tam, Kimberly
    Feizollah, Ali
    Anuar, Nor Badrul
    Salleh, Rosli
    Cavallaro, Lorenzo
    [J]. ACM COMPUTING SURVEYS, 2017, 49 (04)
  • [3] Demystifying the Evolution of Android Malware Variants
    Tang, Lihong
    Chen, Xiao
    Wen, Sheng
    Li, Li
    Grobler, Marthie
    Xiang, Yang
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (04) : 3324 - 3341
  • [4] Characterization of Malware Detection on Android Application
    Hein, Chit La Pyae Myo
    Myo, Khin Mar
    [J]. GENETIC AND EVOLUTIONARY COMPUTING, VOL I, 2016, 387 : 113 - 124
  • [5] A study of android malware detection technology evolution
    National Chung-Shan Institute of Science and Technology, Taoyuan, Taiwan
    [J]. Proc. Int. Carnahan Conf. Secur. Technol., (135-140):
  • [6] Model Checking for Mobile Android Malware Evolution
    Cimitile, Aniello
    Mercaldo, Francesco
    Martinelli, Fabio
    Nardone, Vittoria
    Santone, Antonella
    Vaglini, Gigliola
    [J]. 2017 IEEE/ACM 5TH INTERNATIONAL FME WORKSHOP ON FORMAL METHODS IN SOFTWARE ENGINEERING (FORMALISE) PROCEEDINGS, 2017, : 24 - 30
  • [7] The Evolution of Permission as Feature for Android Malware Detection
    Gaviria de la Puerta, Jose
    Sanz, Borja
    Santos Grueiro, Igor
    Garcia Bringas, Pablo
    [J]. INTERNATIONAL JOINT CONFERENCE: CISIS'15 AND ICEUTE'15, 2015, 369 : 389 - 400
  • [8] An exploratory study on the evolution of Android malware quality
    Mercaldo, Francesco
    Di Sorbo, Andrea
    Visaggio, Corrado Aaron
    Cimitile, Aniello
    Martinelli, Fabio
    [J]. JOURNAL OF SOFTWARE-EVOLUTION AND PROCESS, 2018, 30 (11)
  • [9] A Study of Android Malware Detection Technology Evolution
    Hsieh Wan-Chen
    Wu Chuan-Chi
    Kao Yung-Wei
    [J]. 49TH ANNUAL IEEE INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST), 2015, : 135 - 140
  • [10] Key features for the characterization of Android malware families
    Sedano, Javier
    Gonzalez, Silvia
    Chira, Camelia
    Herrero, Alvaro
    Corchado, Emilio
    Ramon Villar, Jose
    [J]. LOGIC JOURNAL OF THE IGPL, 2017, 25 (01) : 54 - 66