Monet: A User-Oriented Behavior-Based Malware Variants Detection System for Android

被引:68
|
作者
Sun, Mingshen [1 ,2 ]
Li, Xiaolei [3 ]
Lui, John C. S. [1 ,2 ]
Ma, Richard T. B. [3 ]
Liang, Zhenkai [3 ]
机构
[1] Chinese Univ Hong Kong, Dept Comp Sci & Engn, Sha Tin, Peoples R China
[2] Natl Univ Singapore, Singapore 119077, Singapore
[3] Natl Univ Singapore, Sch Comp, Singapore 119077, Singapore
关键词
Malware detection; android; runtime behavior; static structure;
D O I
10.1109/TIFS.2016.2646641
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Android, the most popular mobile OS, has around 78% of the mobile market share. Due to its popularity, it attracts many malware attacks. In fact, people have discovered around 1 million new malware samples per quarter, and it was reported that over 98% of these new malware samples are in fact "derivatives" (or variants) from existing malware families. In this paper, we first show that runtime behaviors of malware's core functionalities are in fact similar within a malware family. Hence, we propose a framework to combine "runtime behavior" with "static structures" to detect malware variants. We present the design and implementation of MONET, which has a client and a backend server module. The client module is a lightweight, in-device app for behavior monitoring and signature generation, and we realize this using two novel interception techniques. The backend server is responsible for large scale malware detection. We collect 3723 malware samples and top 500 benign apps to carry out extensive experiments of detecting malware variants and defending against malware transformation. Our experiments show that MONET can achieve around 99% accuracy in detecting malware variants. Furthermore, it can defend against ten different obfuscation and transformation techniques, while only incurs around 7% performance overhead and about 3% battery overhead. More importantly, MONET will automatically alert users with intrusion details so to prevent further malicious behaviors.
引用
收藏
页码:1103 / 1112
页数:10
相关论文
共 50 条
  • [1] An effective behavior-based Android malware detection system
    Zou, Shihong
    Zhang, Jing
    Lin, Xiaodong
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2015, 8 (12) : 2079 - 2089
  • [2] A Design of Network Behavior-Based Malware Detection System for Android
    Qi, Yincheng
    Cao, Mingjing
    Zhang, Can
    Wu, Ruping
    [J]. ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2014, PT II, 2014, 8631 : 590 - 600
  • [3] On Behavior-based Detection of Malware on Android Platform
    Yu, Wei
    Zhang, Hanlin
    Ge, Linqiang
    Hardy, Rommie
    [J]. 2013 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2013, : 814 - 819
  • [4] Shikra: A behavior-based Android malware detection framework
    Ma Zhao-hui
    Chen Zi-hao
    Wang Xin-ming
    Nic Rui-hua
    Zhao Gan-sen
    Wu Jie-chao
    Ren Xue-qi
    [J]. 2017 INTERNATIONAL CONFERENCE ON GREEN INFORMATICS (ICGI), 2017, : 175 - 184
  • [5] MADAM: Effective and Efficient Behavior-based Android Malware Detection and Prevention
    Saracino, Andrea
    Sgandurra, Daniele
    Dini, Gianluca
    Martinelli, Fabio
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2018, 15 (01) : 83 - 97
  • [6] An Android Behavior-Based Malware Detection Method using Machine Learning
    Chang, Wei-Ling
    Sun, Hung-Min
    Wu, Wei
    [J]. 2016 IEEE INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING, COMMUNICATIONS AND COMPUTING (ICSPCC), 2016,
  • [7] Lightweight Behavior-Based Malware Detection
    Anisetti, Marco
    Ardagna, Claudio A.
    Bena, Nicola
    Giandomenico, Vincenzo
    Gianini, Gabriele
    [J]. MANAGEMENT OF DIGITAL ECOSYSTEMS, MEDES 2023, 2024, 2022 : 237 - 250
  • [8] A BEHAVIOR-BASED APPROACH FOR MALWARE DETECTION
    Mosli, Rayan
    Li, Rui
    Yuan, Bo
    Pan, Yin
    [J]. ADVANCES IN DIGITAL FORENSICS XIII, 2017, 511 : 187 - 201
  • [9] pBMDS: A Behavior-based Malware Detection System for Cellphone Devices
    Xie, Liang
    Zhang, Xinwen
    Seifert, Jean-Pierre
    Zhu, Sencun
    [J]. WISEC 10: PROCEEDINGS ON THE THIRD ACM CONFERENCE ON WIRELESS NETWORK SECURITY, 2010, : 37 - 48
  • [10] An Intelligent Behavior-Based Ransomware Detection System For Android Platform
    Alzahrani, Abdulrahman
    Alshahrani, Hani
    Alshehri, Ali
    Fu, Huirong
    [J]. 2019 FIRST IEEE INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS AND APPLICATIONS (TPS-ISA 2019), 2019, : 28 - 35