Mdroid: Android Based Malware Detection Using Mcm Classifier
نویسندگان
چکیده
Malware analysis and detection has become a prime research area in the case of smartphones, particularly based on android due to its widespread usage and increase in the number of malwares involving huge monetary gains. The exploding number of Android malware calls for automated analysis of the systems. There are two common techniques used for detecting malware, signature based and behaviour based. Signature based detection uses a sequence of bytes that appear in the binary code to identify and detect a family of malware. Behaviour based detection uses features/ artifacts created by malware during execution for identification. In this paper, we propose a new malware classification method based on semantic similarity between two common subgraphs which is effective for the detection and analysis of new threats for which signatures are not available, A behaviour graph is obtained by capturing suspicious API calls during the execution (in a sandboxed environment). We use a labelling mechanism for the API calls which will be regarded as a signature for malicious activity. Selected features are used to train an MCM classifier. On several benchmark datasets, the MCM classifier yields detection accuracy of 97% even with using one-tenth the number of support vectors used by SVMs. Keywords— Android Malware Analysis, API calls, Feature space embedding, Graph kernel, MCM classifier
منابع مشابه
When a Tree Falls: Using Diversity in Ensemble Classifiers to Identify Evasion in Malware Detectors
Machine learning classifiers are a vital component of modern malware and intrusion detection systems. However, past studies have shown that classifier based detection systems are susceptible to evasion attacks in practice. Improving the evasion resistance of learning based systems is an open problem. To address this, we introduce a novel method for identifying the observations on which an ensem...
متن کاملA machine learning approach to anomaly-based detection on Android platforms
The emergence of mobile platforms with increased storage and computing capabilities and the pervasive use of these platforms for sensitive applications such as online banking, e-commerce and the storage of sensitive information on these mobile devices have led to increasing danger associated with malware targeted at these devices. Detecting such malware presents inimitable challenges as signatu...
متن کاملAnalysis of Bayesian classification-based approaches for Android malware detection
Mobile malware has been growing in scale and complexity spurred by the unabated uptake of smartphones worldwide. Android is fast becoming the most popular mobile platform resulting in sharp increase in malware targeting the platform. Additionally, Android malware is evolving rapidly to evade detection by traditional signature-based scanning. Despite current detection measures in place, timely d...
متن کاملA New Android Malware Detection Method Using Bayesian Classification
Mobile malware has been growing in scale and complexity as smartphone usage continues to rise. Android has surpassed other mobile platforms as the most popular whilst also witnessing a dramatic increase in malware targeting the platform. A worrying trend that is emerging is the increasing sophistication of Android malware to evade detection by traditional signature-based scanners. As such, Andr...
متن کاملDetecting Android Malware By Using A Machine Learning Ensemble Method
Android has become the most popular mobile operating system in recent years. As its popularity has increased, so have the number of attacks to the platform. Samples of malware have been found in different popular Android apps markets, including the Google Play store. Most anti-virus software uses a signature-based approach to detect malware, however, it fails to detect unknown malware. Differen...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2016