Anomadroid: profiling Android applications' behaviors for identifying unknown malapps

被引:0
|
作者
Su, Dan [1 ]
Wang, Wei [1 ]
Wang, Xing [1 ]
Liu, Jiqiang [1 ]
机构
[1] Beijing Jiaotong Univ, Sch Comp & Informat Technol, Beijing, Peoples R China
关键词
Android security; anomaly detection; malware detection;
D O I
10.1109/TrustCom.2016.126
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Android has dominated the market of mobile devices. Meanwhile, it has become the main target for attackers. How to detect and analyze Android malicious applications (malapps) is an ongoing challenge. Current malapps have become increasingly sophisticated. In particular, zero-day (unknown) malapps appear very frequently and can evade most detection systems that are based on the signatures or patterns of existing malapps. In this work, we propose a system called Anomadroid (anomaly Android malapp detection system) that profiles the normal behaviors of Android apps based on only benign samples. Any app whose behaviors unacceptably deviate from the normal profile is identified as malicious. We firstly extract 4209 features that are divided into 9 categories such as permissions and APIs, from each app for the profiling. We then use term frequency-inverse document frequency (tf-idf) and employ k-Nearest Neighbor (k-NN) and Principal Component Analysis (PCA) for anomaly detection. We evaluate Anomadroid on a large app set consisting of 15,000 benign apps as well as 1500 malapps. The experimental results show that our system is better than existing methods and achieves a detection rate as 94.08% with false positive rate as 16.15%.
引用
收藏
页码:691 / 698
页数:8
相关论文
共 46 条
  • [41] Identifying the origin of lung-specific cancer of unknown primary based on comprehensive genomic profiling optimized with DNA methylation
    Fan, Y.
    Chen, K.
    ANNALS OF ONCOLOGY, 2021, 32 : S397 - S397
  • [42] Identifying the Primary Site Using Gene Expression Profiling in Patients with Carcinoma of an Unknown Primary (CUP): A Feasibility Study from the GEFCAPI
    Gross-Goupil, Marine
    Massard, Christophe
    Lesimple, Thierry
    Merrouche, Yacine
    Blot, Emmanule
    Loriot, Yohan
    Mathieu, Marie C.
    Fizazi, Karim
    ONKOLOGIE, 2012, 35 (1-2): : 54 - 55
  • [43] Cost-effectiveness of using a gene expression profiling test to aid in identifying the primary tumour in patients with cancer of unknown primary
    M B Hannouf
    E Winquist
    S M Mahmud
    M Brackstone
    S Sarma
    G Rodrigues
    P Rogan
    J S Hoch
    G S Zaric
    The Pharmacogenomics Journal, 2017, 17 : 286 - 300
  • [44] Identifying the primary site using gene expression profiling in patients with carcinoma of an unknown primary (CUP): a feasibility study from the GEFCAPI
    Gross-Goupil, M.
    Loriot, Y.
    Lesimple, T.
    Merrouche, Y.
    Blot, E.
    Massard, C.
    Mathieu, M. C.
    Fizazi, K.
    EJC SUPPLEMENTS, 2009, 7 (02): : 148 - 148
  • [45] Cost-effectiveness of using a gene expression profiling test to aid in identifying the primary tumour in patients with cancer of unknown primary
    Hannouf, M. B.
    Winquist, E.
    Mahmud, S. M.
    Brackstone, M.
    Sarma, S.
    Rodrigues, G.
    Rogan, P.
    Hoch, J. S.
    Zaric, G. S.
    PHARMACOGENOMICS JOURNAL, 2017, 17 (03): : 286 - 300
  • [46] apk2vec: Semi-supervised multi-view representation learning for profiling Android applications
    Narayanan, Annamalai
    Soh, Charlie
    Chen, Lihui
    Liu, Yang
    Wang, Lipo
    2018 IEEE INTERNATIONAL CONFERENCE ON DATA MINING (ICDM), 2018, : 357 - 366