Kernel-based Behavior Analysis for Android Malware Detection

Computational Intelligence and Security(2011)

引用 110|浏览4
暂无评分
摘要
The most major threat of Android users is malware infection via Android application markets. In case of the Android Market, as security inspections are not applied for many users have uploaded applications. Therefore, malwares, e.g., Geimini and Droid Dream will attempt to leak personal information, getting root privilege, and abuse functions of the smart phone. An audit framework called log cat is implemented on the Dalvik virtual machine to monitor the application behavior. However, only the limited events are dumped, because an application developers use the log cat for debugging. The behavior monitoring framework that can audit all activities of applications is important for security inspections on the market places. In this paper, we propose a kernel-base behavior analysis for android malware inspection. The system consists of a log collector in the Linux layer and a log analysis application. The log collector records all system calls and filters events with the target application. The log analyzer matches activities with signatures described by regular expressions to detect a malicious activity. Here, signatures of information leakage are automatically generated using the smart phone IDs, e.g., phone number, SIM serial number, and Gmail accounts. We implement a prototype system and evaluate 230 applications in total. The result shows that our system can effectively detect malicious behaviors of the unknown applications.
更多
查看译文
关键词
application developer,log collector record,log analysis application,security inspection,application behavior,android malware detection,log cat,log collector,kernel-based behavior analysis,target application,log analyzer,android application market,systems analysis,regular expression,application development,humanoid robot,linux,android,operating systems,system monitoring,behavior analysis,virtual machines,operating system,mobile computing,virtual machine,malware,humanoid robots,mobile communication
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要