On Existence of Common Malicious System Call Codes in Android Malware Families

被引:19
|
作者
Surendran, Roopak [1 ]
Thomas, Tony [1 ]
Emmanuel, Sabu [2 ]
机构
[1] Cochin Univ Sci & Technol, Indian Inst Informat Technol & Management Kerala, Res Ctr, Thiruvananthapuram 695581, Kerala, India
[2] Indian Inst Technol, Dept Elect Engn, Palakkad 678557, India
关键词
Malware; Androids; Humanoid robots; Machine learning; Markov processes; Feature extraction; Static analysis; Asymptotic equipartition property (AEP); android malware; dynamic malware detection; ergodic Markov chain; system calls;
D O I
10.1109/TR.2020.2982537
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Most of the existing Android malware detection mechanisms are based on machine learning algorithms. The problem with the machine learning approaches is the difficulty in finding the best features that uniquely characterize the malwares. Hence, in this article we explore the property that uniquely characterizes Android malware applications. Toward this, we model the system call sequence generated by a malware application as a stationary first-order ergodic Markov chain and prove the existence of typical patterns which contains the malicious system call code of the application. In our implementation, we find the occurrence of common malicious system call codes in the system call sequence of several malware families. Finally a malware detection mechanism is proposed based on the occurrence of malicious system call codes in the system call sequence of an application. We obtain a consistent accuracy of around 0.95 in balanced, slightly unbalanced, and highly unbalanced data sets. In the balanced and slightly unbalanced data sets we obtain greater precision than 0.90; whereas in the highly unbalanced data sets the precision obtained are slightly lower at 0.72.
引用
收藏
页码:248 / 260
页数:13
相关论文
共 50 条
  • [1] Dynamic detection on android malicious codes using API call sequences
    Shi, Dong-Xian
    Xu, Zhi-Wei
    Jiang, Jie
    Zhang, Hui
    Pan, Yong-Tao
    Boletin Tecnico/Technical Bulletin, 2017, 55 (12): : 436 - 446
  • [2] Fingerprinting Android malware families
    Nannan Xie
    Xing Wang
    Wei Wang
    Jiqiang Liu
    Frontiers of Computer Science, 2019, 13 : 637 - 646
  • [3] Fingerprinting Android malware families
    Xie, Nannan
    Wang, Xing
    Wang, Wei
    Liu, Jiqiang
    FRONTIERS OF COMPUTER SCIENCE, 2019, 13 (03) : 637 - 646
  • [4] Android Gaming Malware Detection Using System Call Analysis
    Jaiswal, Mayank
    Malik, Yasir
    Jaafar, Fehmi
    2018 6TH INTERNATIONAL SYMPOSIUM ON DIGITAL FORENSIC AND SECURITY (ISDFS), 2018, : 251 - 255
  • [5] Android malware detection based on system call sequences and LSTM
    Xiao, Xi
    Zhang, Shaofeng
    Mercaldo, Francesco
    Hu, Guangwu
    Sangaiah, Arun Kumar
    MULTIMEDIA TOOLS AND APPLICATIONS, 2019, 78 (04) : 3979 - 3999
  • [6] Android malware detection based on system call sequences and LSTM
    Xi Xiao
    Shaofeng Zhang
    Francesco Mercaldo
    Guangwu Hu
    Arun Kumar Sangaiah
    Multimedia Tools and Applications, 2019, 78 : 3979 - 3999
  • [7] MsDroid: Identifying Malicious Snippets for Android Malware Detection
    He, Yiling
    Li, Yiping
    Wu, Lei
    Yang, Ziqi
    Ren, Kui
    Qin, Zhan
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (03) : 2025 - 2039
  • [8] On the use of artificial malicious patterns for android malware detection
    Jerbi, Manel
    Dagdia, Zaineb Chelly
    Bechikh, Slim
    Ben Said, Lamjed
    COMPUTERS & SECURITY, 2020, 92 (92)
  • [9] Lexical Mining of Malicious URLs for Classifying Android Malware
    Wang, Shanshan
    Yan, Qiben
    Chen, Zhenxiang
    Wang, Lin
    Spolaor, Riccardo
    Yang, Bo
    Conti, Mauro
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2018, PT I, 2018, 254 : 248 - 263
  • [10] Modeling and Capturing Malicious Behavior to Detect Android Malware
    El AassaL, Ayman
    Huang, Shou-Hsuan Stephen
    PROCEEDINGS OF NINTH INTERNATIONAL CONGRESS ON INFORMATION AND COMMUNICATION TECHNOLOGY, VOL 2, ICICT 2024, 2024, 1012 : 325 - 335