On the use of artificial malicious patterns for android malware detection

被引:34
|
作者
Jerbi, Manel [1 ]
Dagdia, Zaineb Chelly [2 ,3 ]
Bechikh, Slim [1 ]
Ben Said, Lamjed [1 ]
机构
[1] Univ Tunis, SMART Lab, ISG Campus, Tunis, Tunisia
[2] Univ Lorraine, LORIA, INRIA, CNRS, F-54000 Nancy, France
[3] Inst Super Gest Tunis, LARODEC, Tunis, Tunisia
基金
欧盟地平线“2020”;
关键词
Malware detection; API call sequences; Artificial malicious patterns; Evolutionary algorithm; Android; CLASSIFICATION; SYSTEM;
D O I
10.1016/j.cose.2020.101743
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Malware programs currently represent the most serious threat to computer information systems. Despite the performed efforts of researchers in this field, detection tools still have limitations for one main reason. Actually, malware developers usually use obfuscation techniques consisting in a set of transformations that make the code and/or its execution difficult to analyze by hindering both manual and automated inspections. These techniques allow the malware to escape the detection tools, and hence to be seen as a benign program. To solve the obfuscation issue, many researchers have proposed to extract frequent Application Programming Interface (API) call sequences from previously encountered malware programs using pattern mining techniques and hence, build a base of fraudulent behaviors. Based on this process, it is worth mentioning that the performance of the detection process heavily depends on the base of examples of malware behaviors; also called malware patterns. In order to deal with this shortcoming, a dynamic detection method called Artificial Malware-based Detection (AMD) is proposed in this paper. AMD makes use of not only extracted malware patterns but also artificially generated ones. The artificial malware patterns are generated using an evolutionary (genetic) algorithm. The latter evolves a population of API call sequences with the aim to find new malware behaviors following a set of well-defined evolution rules. The artificial fraudulent behaviors are subsequently inserted into the base of examples in order to enrich it with unseen malware patterns. The main motivation behind the proposed AMD approach is to diversify the base of malware examples in order to maximize the detection rate. AMD has been tested on different Android malware data sets and compared against recent prominent works using commonly employed performance metrics. The performance analysis of the obtained results shows the merits of our AMD novel approach. (C) 2020 Elsevier Ltd. All rights reserved.
引用
下载
收藏
页数:22
相关论文
共 50 条
  • [31] A Survey on Android Malware Detection Techniques
    Riasat, Rubata
    Sakeena, Muntaha
    Wang, Chong
    Sadiq, Abdul Hannan
    Wang, Yong-ji
    INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATION AND NETWORK ENGINEERING (WCNE 2016), 2016,
  • [32] Characterization of Malware Detection on Android Application
    Hein, Chit La Pyae Myo
    Myo, Khin Mar
    GENETIC AND EVOLUTIONARY COMPUTING, VOL I, 2016, 387 : 113 - 124
  • [33] A Comparison of Features for Android Malware Detection
    Leeds, Matthew
    Keffeler, Miclain
    Atkison, Travis
    PROCEEDINGS OF THE SOUTHEAST CONFERENCE ACM SE'17, 2017, : 63 - 68
  • [34] Category Based Malware Detection for Android
    Grampurohit, Vijayendra
    Kumar, Vijay
    Rawat, Sanjay
    Rawat, Shatrunjay
    SECURITY IN COMPUTING AND COMMUNICATIONS, 2014, 467 : 239 - 249
  • [35] Android Malware Detection & Protection: A Survey
    Arshad, Saba
    Khan, Abid
    Shah, Munam Ali
    Ahmed, Mansoor
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2016, 7 (02) : 463 - 475
  • [36] A pragmatic android malware detection procedure
    Palumbo, Paolo
    Sayfullina, Luiza
    Komashinskiy, Dmitriy
    Eirola, Emil
    Karhunen, Juha
    COMPUTERS & SECURITY, 2017, 70 : 689 - 701
  • [37] Runtime Detection Framework for Android Malware
    Kim, TaeGuen
    Kang, BooJoong
    Im, Eul Gyu
    MOBILE INFORMATION SYSTEMS, 2018, 2018
  • [38] A framework for Android Malware detection and classification
    Murtaz, Muhammad
    Azwar, Hassan
    Ali, Syed Baqir
    Rehman, Saad
    2018 5TH IEEE INTERNATIONAL CONFERENCE ON ENGINEERING TECHNOLOGIES AND APPLIED SCIENCES (IEEE ICETAS), 2018,
  • [39] A Hybrid Detection Method for Android Malware
    Fang, Qi
    Yang, Xiaohui
    Ji, Ce
    PROCEEDINGS OF 2019 IEEE 3RD INFORMATION TECHNOLOGY, NETWORKING, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (ITNEC 2019), 2019, : 2127 - 2132
  • [40] MADLIRA: A Tool for Android Malware Detection
    Khanh Huu The Dam
    Touili, Tayssir
    ICISSP: PROCEEDINGS OF THE 7TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2021, : 670 - 675