"Andromaly": a behavioral malware detection framework for android devices

被引:413
|
作者
Shabtai, Asaf [1 ]
Kanonov, Uri [1 ]
Elovici, Yuval [1 ]
Glezer, Chanan [1 ]
Weiss, Yael [1 ]
机构
[1] Ben Gurion Univ Negev, Dept Informat Syst Engn, Deutsch Telekom Labs, IL-84105 Beer Sheva, Israel
关键词
Mobile devices; Machine learning; Malware; Security; Android; MOBILE; CLASSIFICATION;
D O I
10.1007/s10844-010-0148-x
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
This article presents Andromaly-a framework for detecting malware on Android mobile devices. The proposed framework realizes a Host-based Malware Detection System that continuously monitors various features and events obtained from the mobile device and then applies Machine Learning anomaly detectors to classify the collected data as normal (benign) or abnormal (malicious). Since no malicious applications are yet available for Android, we developed four malicious applications, and evaluated Andromaly's ability to detect new malware based on samples of known malware. We evaluated several combinations of anomaly detection algorithms, feature selection method and the number of top features in order to find the combination that yields the best performance in detecting new malware on Android. Empirical results suggest that the proposed framework is effective in detecting malware on mobile devices in general and on Android in particular.
引用
收藏
页码:161 / 190
页数:30
相关论文
共 50 条
  • [1] “Andromaly”: a behavioral malware detection framework for android devices
    Asaf Shabtai
    Uri Kanonov
    Yuval Elovici
    Chanan Glezer
    Yael Weiss
    [J]. Journal of Intelligent Information Systems, 2012, 38 : 161 - 190
  • [2] Behavioral Malware Detection Approaches for Android
    Amin, Mohammad Ram
    Zaman, Mehedee
    Hossain, Md. Shohrab
    Atiquzzamant, Mohammed
    [J]. 2016 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2016,
  • [3] Runtime Detection Framework for Android Malware
    Kim, TaeGuen
    Kang, BooJoong
    Im, Eul Gyu
    [J]. MOBILE INFORMATION SYSTEMS, 2018, 2018
  • [4] A framework for Android Malware detection and classification
    Murtaz, Muhammad
    Azwar, Hassan
    Ali, Syed Baqir
    Rehman, Saad
    [J]. 2018 5TH IEEE INTERNATIONAL CONFERENCE ON ENGINEERING TECHNOLOGIES AND APPLIED SCIENCES (IEEE ICETAS), 2018,
  • [5] Permission based malware detection in android devices
    Ilham, Soussi
    Abderrahim, Ghadi
    Abdelhakim, Boudhir Anouar
    [J]. PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON SMART CITY APPLICATIONS (SCA'18), 2018,
  • [6] Research Trends in Malware Detection on Android Devices
    Aneja, Leesha
    Babbar, Sakshi
    [J]. DATA SCIENCE AND ANALYTICS, 2018, 799 : 629 - 642
  • [7] Malware Detection with Confidence Guarantees on Android Devices
    Georgiou, Nestoras
    Konstantinidis, Andreas
    Papadopoulos, Harris
    [J]. ARTIFICIAL INTELLIGENCE APPLICATIONS AND INNOVATIONS, AIAI 2016, 2016, 475 : 407 - 418
  • [8] Machine learning-based malware detection on Android devices using behavioral features
    Urmila, T. S.
    [J]. MATERIALS TODAY-PROCEEDINGS, 2022, 62 : 4659 - 4664
  • [9] Permission Extraction Framework for Android Malware Detection
    Ghasempour, Ali
    Sani, Nor Fazlida Mohd
    Abari, Ovye John
    [J]. International Journal of Advanced Computer Science and Applications, 2020, 11 (11): : 463 - 475
  • [10] Permission Extraction Framework for Android Malware Detection
    Ghasempour, Ali
    Sani, Nor Fazlida Mohd
    Abari, Ovye John
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2020, 11 (11) : 463 - 475