Anomadroid: profiling Android applications' behaviors for identifying unknown malapps

被引:0
|
作者
Su, Dan [1 ]
Wang, Wei [1 ]
Wang, Xing [1 ]
Liu, Jiqiang [1 ]
机构
[1] Beijing Jiaotong Univ, Sch Comp & Informat Technol, Beijing, Peoples R China
关键词
Android security; anomaly detection; malware detection;
D O I
10.1109/TrustCom.2016.126
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Android has dominated the market of mobile devices. Meanwhile, it has become the main target for attackers. How to detect and analyze Android malicious applications (malapps) is an ongoing challenge. Current malapps have become increasingly sophisticated. In particular, zero-day (unknown) malapps appear very frequently and can evade most detection systems that are based on the signatures or patterns of existing malapps. In this work, we propose a system called Anomadroid (anomaly Android malapp detection system) that profiles the normal behaviors of Android apps based on only benign samples. Any app whose behaviors unacceptably deviate from the normal profile is identified as malicious. We firstly extract 4209 features that are divided into 9 categories such as permissions and APIs, from each app for the profiling. We then use term frequency-inverse document frequency (tf-idf) and employ k-Nearest Neighbor (k-NN) and Principal Component Analysis (PCA) for anomaly detection. We evaluate Anomadroid on a large app set consisting of 15,000 benign apps as well as 1500 malapps. The experimental results show that our system is better than existing methods and achieves a detection rate as 94.08% with false positive rate as 16.15%.
引用
收藏
页码:691 / 698
页数:8
相关论文
共 46 条
  • [31] AsDroid: Detecting Stealthy Behaviors in Android Applications by User Interface and Program Behavior Contradiction
    Huang, Jianjun
    Zhang, Xiangyu
    Tan, Lin
    Wang, Peng
    Liang, Bin
    36TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING (ICSE 2014), 2014, : 1036 - 1046
  • [32] DroidMiner: Automated Mining and Characterization of Fine-grained Malicious Behaviors in Android Applications
    Yang, Chao
    Xu, Zhaoyan
    Gu, Guofei
    Yegneswaran, Vinod
    Porras, Phillip
    COMPUTER SECURITY - ESORICS 2014, PT I, 2014, 8712 : 163 - 182
  • [33] DAppHunter: Identifying Inconsistent Behaviors of Blockchain-based Decentralized Applications
    Zhou, Jianfei
    Jiang, Tianxing
    Wang, Haijun
    Wu, Meng
    Chen, Ting
    2023 IEEE/ACM 45TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING: SOFTWARE ENGINEERING IN PRACTICE, ICSE-SEIP, 2023, : 24 - 35
  • [34] Identifying Performance Inefficiencies Via Object-Centric Profiling for Java Programs Running on JVM and Android Runtime
    Li, Bolun
    ProQuest Dissertations and Theses Global, 2022,
  • [35] Identifying Battery-Draining Applications by Monitoring Behavior in Screen-Off State in Android
    Kurihara, Shun
    Fukuda, Shoki
    Hamanaka, Shintaro
    Oguchi, Masato
    Yamaguchi, Saneyasu
    2016 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS-TAIWAN (ICCE-TW), 2016, : 167 - 168
  • [36] OATs'inside: Retrieving Object Behaviors From Native-based Obfuscated Android Applications
    Graux, Pierre
    Lalande, Jean-Francois
    Tong, Valerie Viet Triem
    Wilke, Pierre
    DIGITAL THREATS: RESEARCH AND PRACTICE, 2023, 4 (02):
  • [37] Droidlnjector: A process injection-based dynamic tracking system for runtime behaviors of Android applications
    Fan, Wenhao
    Sang, Yaohui
    Zhang, Daishuai
    Sun, Ran
    Liu, Yuan'an
    COMPUTERS & SECURITY, 2017, 70 : 224 - 237
  • [38] Identifying the Fraudulent Users for E-commerce Applications Based on the Access Behaviors
    Chen, Rujia
    Xie, Yi
    ADVANCED INTELLIGENT COMPUTING TECHNOLOGY AND APPLICATIONS, PT I, ICIC 2024, 2024, 14875 : 25 - 36
  • [39] Profiling Users from Online Social Behaviors with Applications for Tencent Social Ads
    Law, Ching
    KDD'16: PROCEEDINGS OF THE 22ND ACM SIGKDD INTERNATIONAL CONFERENCE ON KNOWLEDGE DISCOVERY AND DATA MINING, 2016, : 409 - 409
  • [40] Identifying the Origin of Lung-Specific Cancer of Unknown Primary Based on Comprehensive Genomic Profiling Optimized With DNA Methylation
    Chen, K.
    Fan, Y.
    JOURNAL OF THORACIC ONCOLOGY, 2021, 16 (10) : S1149 - S1150