APK Auditor: Permission-based Android malware detection system
نویسندگان
چکیده
Android operating system has the highest market share in 2014; making it the most widely used mobile operating system in the world. This fact makes Android users the biggest target group for malware developers. Trend analyses show large increase in mobile malware targeting the Android platform. Android's security mechanism is based on an instrument that informs users about which permissions the application needs to be granted before installing them. This permission system provides an overview of the application and may help gain awareness about the risks. However, we do not have enough information to conclude that standard users read or digital investigators understand these permissions and their implications. Digital investigators need to be on the alert for the presence of malware when examining Android devices, and can benefit from supporting tools that help them understand the capabilities of such malicious code. This paper presents a permission-based Android malware detection system, APK Auditor that uses static analysis to characterize and classify Android applications as benign or malicious. APK Auditor consists of three components: (1) A signature database to store extracted information about applications and analysis results, (2) an Android client which is used by endusers to grant application analysis requests, and (3) a central server responsible for communicating with both signature database and smartphone client and managing whole analysis process. To test system performance, 8762 applications in total, 1853 benign applications from Google's Play Store and 6909 malicious applications from different sources were collected and analyzed by the system developed. The results show that APK Auditor is able to detect most well-known malwares and highlights the ones with a potential in approximately 88% accuracy with a 0.925 specificity. © 2015 Elsevier Ltd. All rights reserved.
منابع مشابه
Permission based Malware Analysis & Detection in Android
Android being a leading and the most popular operating system for smart phones and tablets, has also become a prime target for the attackers due to its growing users and it being an open source platform. This document describes the work done in detecting malware in the Android platform by performing static analysis on the permission based framework in Android platform. In our work, we have extr...
متن کاملStudy of Malware Detection Technique for Apk and SDK File Using Artificial Immune
The word wide sharply increase in the number of smartphones user, the Android platform pose to becoming a market fugleman that makes the need for malware analysis on this platform an urgent issue. The current Artificial Immune Based malware detection systems they focus on traditional computers that uses information from OS or network, but the smartphone software behavior has its own structure a...
متن کاملHunting ELFs: An investigation into Android malware detection
In the depths of Android mobile applications all over the world, malicious ELFs are lying dormant and hidden, awaiting activation by the malware that controls them. But fear not! Though they may lie in secret, for those who would hunt them these ELFs leave a trail that can be followed. This is the story of the hunt and how these ELFs came to reveal themselves.a aThis article is published online...
متن کاملDetection of Malware on Android based on Application Features
Threat of mobile malware is increasing day by day. Since Android is the most popular and maximum sold mobile phone, there is an increasing threat of malware on Android based mobile device. The different antimalware products available in market can detect the malware in its original form. But they cannot detect the malware after applying some form of obfuscation or transformation to the malware....
متن کاملThree-Phase Detection and Classification for Android Malware Based on Common Behaviors
Android is one of the most popular operating systems used in mobile devices. Its popularity also renders it a common target for attackers. We propose an efficient and accurate three-phase behavior-based approach for detecting and classifying malicious Android applications. In the proposed approach, the first two phases detect a malicious application and the final phase classifies the detected m...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- Digital Investigation
دوره 13 شماره
صفحات -
تاریخ انتشار 2015